Fresh SharePoint Vulnerability Exploited Soon After Disclosure

A critical vulnerability in Microsoft SharePoint, disclosed just last week, is already being exploited by threat actors. The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning to federal agencies, urging them to patch the flaw within three days.

The vulnerability, tracked as CVE-2026-58644, allows an attacker with at least Site Owner privileges to inject and execute code remotely on a SharePoint Server. This is a classic example of a deserialization of untrusted data issue, which can have devastating consequences if exploited. Microsoft patched the flaw in its July 2026 Patch Tuesday updates, but it’s clear that some attackers were already aware of it.

The CISA warning highlights the importance of timely patching and vulnerability management. As we’ve seen time and time again, a newly disclosed vulnerability is often exploited by attackers before a fix can be deployed to users. In this case, Microsoft had initially marked CVE-2026-58644 as unexploited, but it’s now clear that attackers were already exploiting the flaw.

The CISA alert also includes two other vulnerabilities in its list of Known Exploited Vulnerabilities (KEV): CVE-2026-25089 and CVE-2026-39808. These are OS command injection flaws in Fortinet FortiSandbox appliances, which were patched in June and April respectively. Both vulnerabilities allow attackers to execute arbitrary code or commands on vulnerable devices.

It’s worth noting that these vulnerabilities were not only exploited by attackers but also added to the CISA KEV list as part of its ongoing efforts to prioritize patching and vulnerability management for federal agencies. This highlights the importance of following industry best practices, such as regularly reviewing and applying security patches, to mitigate potential risks.

The recent exploitation of CVE-2026-58644 is a stark reminder that attackers are constantly evolving and adapting their tactics to take advantage of newly disclosed vulnerabilities. As such, it’s essential for organizations to prioritize patching and vulnerability management, not just for SharePoint but also for other critical systems.

In practical terms, this means that all organizations using SharePoint should review the latest Microsoft Patch Tuesday updates and apply the relevant patches as soon as possible. Additionally, administrators should regularly review their security configurations and ensure that all systems are up-to-date with the latest security patches to prevent potential exploitation of vulnerabilities like CVE-2026-58644.


Source: SecurityWeek — 2026-07-17