UPDATE: Microsoft SharePoint Server Vulnerabilities – Immediate Patching Required

Security Bulletin

⚠ Immediate Action Required

Two critical SharePoint Server vulnerabilities have been added to CISA's Known Exploited Vulnerabilities catalog. Federal agencies had a remediation deadline of July 19, 2026. All organizations should patch immediately.

CVE-2026-58644

A deserialization flaw in SharePoint Server affecting multiple versions, enabling authenticated attackers to execute arbitrary code. CISA added this CVE to its Known Exploited Vulnerabilities (KEV) catalog on July 16, 2026. No public proof-of-concept exploit code exists at time of publication. SharePoint Online is not affected.

CVE-2026-50522

Carries a CVSS score of 9.8 and allows delivery of malicious .NET deserialization payloads through vulnerable SharePoint endpoints. Public PoC exploit code exists for this vulnerability. SharePoint Online is not affected.

Affected Versions & Patches

  • SharePoint Subscription Edition: KB5002882
  • SharePoint 2019: KB5002883 / KB5002885
  • SharePoint 2016: KB5002891 / KB5002892

Hardening Steps

  • Rotate ASP.NET machine keys after patching
  • Restart IIS on all affected servers
  • Enable AMSI (Antimalware Scan Interface) for SharePoint
  • Enforce MFA for all SharePoint administrative access
  • Audit and restrict administrative privileges

Workarounds do not eliminate risk. Full patching is the only reliable mitigation.

References

Stay Ahead of Critical Vulnerabilities