Fresh SharePoint Vulnerability Exploited Soon After Disclosure
Reported exploitedSharePoint Server Subscription EditionSharePoint Server 2019Our summary
A critical remote code execution vulnerability in Microsoft SharePoint, tracked as CVE-2026-58644, has been actively exploited just days after its disclosure. The flaw, rated with a CVSS score of 9.8, allows authenticated attackers with Site Owner privileges to inject and execute arbitrary code on affected servers. Microsoft addressed the issue during its July 2026 Patch Tuesday release. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, urging immediate patching for SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.