<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/three-microsoft-sharepoint-vulnerabilities-under-active-exploitation-cisa-warns-ntyvrzluf" -->

---
title: Three Microsoft SharePoint vulnerabilities under active...
description: CISA has added three Microsoft SharePoint vulnerabilities to its Known Exploited Vulnerabilities catalog. The most critical is CVE-2026-58644, a CVSS 9.8...
canonical: https://daily.dev/posts/three-microsoft-sharepoint-vulnerabilities-under-active-exploitation-cisa-warns-ntyvrzluf
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Three Microsoft SharePoint vulnerabilities under active exploitation, CISA warns | daily.dev
og:description: CISA has added three Microsoft SharePoint vulnerabilities to its Known Exploited Vulnerabilities catalog. The most critical is CVE-2026-58644, a CVSS 9.8...
og:url: https://daily.dev/posts/three-microsoft-sharepoint-vulnerabilities-under-active-exploitation-cisa-warns-ntyvrzluf
og:image: https://api.daily.dev/og/posts/ntYVrZLUf.png
og:image:alt: Three Microsoft SharePoint vulnerabilities under active exploitation, CISA warns
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Three Microsoft SharePoint vulnerabilities under active exploitation, CISA warns

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 0 upvotes · 0 comments

## Summary

CISA has added three Microsoft SharePoint vulnerabilities to its Known Exploited Vulnerabilities catalog. The most critical is CVE-2026-58644, a CVSS 9.8 unauthenticated RCE flaw affecting on-premises SharePoint Server 2016, 2019, and Subscription Edition, caused by deserialization of untrusted data. Microsoft released patches on July 14, 2026. Affected organizations should apply the July 14 updates immediately, enable AMSI integration on SharePoint servers, and monitor Defender/AMSI detection signatures. This issue only affects on-premises deployments — SharePoint Online and Microsoft 365 users are not impacted. CISA's KEV listing confirms active exploitation in real attacks, making patching an emergency priority for government agencies and enterprises still running local SharePoint infrastructure.

## Content

CISA has added three Microsoft SharePoint vulnerabilities to its Known Exploited Vulnerabilities catalog, with one critical unauthenticated remote code execution flaw drawing particular attention from security teams.

## The critical RCE: CVE-2026-58644

The most severe of the three is CVE-2026-58644, a CVSS 9.8 unauthenticated RCE vulnerability affecting on-premises SharePoint Server 2016, 2019, and Subscription Edition. The root cause is deserialization of untrusted data, meaning an attacker with no credentials can send a crafted request and execute arbitrary code on the server.

Microsoft confirmed active exploitation and released patches on July 14, 2026. CISA added the flaw to its KEV catalog on July 16. Two additional critical vulnerabilities are reportedly compounding the risk, though patches for the full set have not fully remediated all issues according to current reporting.

## What to do now

If you're running on-premises SharePoint, the immediate steps are:

- **Apply the July 14 security updates** across all affected versions (2016, 2019, Subscription Edition)
- **Enable AMSI integration** on SharePoint servers — Microsoft's Antimalware Scan Interface provides an additional detection layer for deserialization attacks
- **Monitor Defender and AMSI detection signatures** specific to this CVE

Rapid7's InsightVM, Nexpose, and Exposure Command products include an authenticated check for CVE-2026-58644 if you need to verify patch status across your environment.

## Context worth noting

This is an on-premises problem, not SharePoint Online. Organizations that migrated to Microsoft 365 aren't affected. For everyone still running local SharePoint infrastructure — which includes a lot of government agencies and enterprises with compliance requirements — this is a genuine emergency patch situation, not a "get to it next cycle" item.

The fact that CISA is flagging active exploitation means attackers are already using this in real attacks, not just proof-of-concept research. Treat the July 14 patches as mandatory.

## Similar posts on daily.dev

- [CISA: Microsoft SharePoint RCE flaw now actively exploited](https://daily.dev/posts/cisa-microsoft-sharepoint-rce-flaw-now-actively-exploited-5qwo6lfyk) · BleepingComputer · 0 upvotes · 0 comments
- [CISA: Microsoft SharePoint flaw now exploited in ransomware attacks](https://daily.dev/posts/cisa-microsoft-sharepoint-flaw-now-exploited-in-ransomware-attacks-vx5dy86qs) · BleepingComputer · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#microsoft](https://daily.dev/tags/microsoft), [#sharepoint](https://daily.dev/tags/sharepoint)

[View this post on daily.dev](https://daily.dev/posts/three-microsoft-sharepoint-vulnerabilities-under-active-exploitation-cisa-warns-ntyvrzluf)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Three Microsoft SharePoint vulnerabilities under active exploitation, CISA warns","url":"https://daily.dev/posts/three-microsoft-sharepoint-vulnerabilities-under-active-exploitation-cisa-warns-ntyvrzluf","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/three-microsoft-sharepoint-vulnerabilities-under-active-exploitation-cisa-warns-ntyvrzluf"},"datePublished":"2026-07-17T18:47:19.094Z","dateModified":"2026-07-17T18:48:00.543Z","description":"CISA has added three Microsoft SharePoint vulnerabilities to its Known Exploited Vulnerabilities catalog. The most critical is CVE-2026-58644, a CVSS 9.8...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/403310fc83643451d0e643aaed18bd42?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/403310fc83643451d0e643aaed18bd42?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/three-microsoft-sharepoint-vulnerabilities-under-active-exploitation-cisa-warns-ntyvrzluf","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,microsoft,sharepoint","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Three Microsoft SharePoint vulnerabilities under active exploitation, CISA warns"}]}
```

