Fresh SharePoint Vulnerability Exploited Soon After Disclosure

A critical vulnerability in Microsoft SharePoint is being actively exploited by threat actors just days after its disclosure. The flaw, tracked as CVE-2026-58644 and fixed in July’s Patch Tuesday updates, allows attackers to execute arbitrary code remotely on a SharePoint Server, putting sensitive data at risk.

The vulnerability affects authenticated users with Site Owner privileges, making it potentially accessible to anyone who has been granted elevated permissions within an organization. Once exploited, the attacker can inject and run malicious code on the server, giving them unrestricted access to sensitive information and potential control over the entire system.

Microsoft’s security updates addressed several SharePoint vulnerabilities, including CVE-2026-56164, which was already being exploited in the wild as a zero-day flaw. The July patches also resolved CVE-2026-55040, a critical security bypass weakness that could allow attackers to disclose files and modify data. Although CVE-2026-58644 was not initially marked as exploited, Microsoft has since updated its advisory to note that exploitation had been detected.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days, as mandated by BOD 26-04. CISA has also included CVE-2026-25089 and CVE-2026-39808 in the KEV list, which are OS command injection flaws in Fortinet’s FortiSandbox that were patched in June and April.

Both of these security defects allow attackers to execute arbitrary code or commands on vulnerable appliances. In mid-June, exploit intelligence company Defused flagged both as exploited in the wild. Federal agencies are required to patch the three exploited bugs within three days, highlighting the importance of timely vulnerability remediation.

This incident serves as a reminder that even with the latest security patches and updates in place, organizations can still be vulnerable to attacks if they fail to apply them promptly. It’s essential for organizations to prioritize regular software updates, security audits, and employee education to prevent such incidents from occurring.

To mitigate the risk of CVE-2026-58644, we recommend that all SharePoint users update their systems as soon as possible and ensure that all patches are properly applied. Furthermore, organizations should regularly review their vulnerability management processes to identify and address potential weaknesses before they can be exploited by attackers. By taking proactive steps towards cybersecurity, organizations can significantly reduce the risk of data breaches and protect sensitive information from falling into the wrong hands.


Source: SecurityWeek — 2026-07-17