Microsoft SharePoint on‑premises flaws exploited; patches and key rotation urged
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several on‑premises Microsoft SharePoint vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming active weaponisation. The most critical issues include CVE‑2026‑58644, a deserialization flaw that enables remote code execution (CVSS 9.8), and CVE‑2026‑50522, which allows unauthenticated attackers to steal SharePoint machine keys. A publicly released exploit appeared on July 20, and honeypot data showed successful compromises within 24 hours.
Experts warn that applying the July patch alone does not remove the threat because the stolen machine keys permit persistence. Immediate remediation steps include installing the Microsoft July patch, integrating the Antimalware Scan Interface (AMSI), rotating SharePoint machine keys, segmenting the SharePoint servers from the rest of the network, and complying with Binding Operational Directive 22‑01. Federal agencies have a remediation deadline of July 19, 2026.