SharePoint Zero-Day Sees Mass Exploitation in Wake of Record-Breaking Patch Tuesday

Microsoft’s July 2026 Patch Tuesday release, published on July 14, set a new record for the largest security update in the company’s history, addressing over 600 vulnerabilities across Windows, Office, SharePoint Server, Active Directory Federation Services, Exchange Server, Azure, and SQL Server. The release included fixes for 62 Critical-rated flaws and two vulnerabilities that Microsoft confirmed were already being exploited in the wild, along with one additional zero-day that was publicly disclosed but unpatched. The sheer scale of the update, roughly triple the volume of vulnerabilities disclosed the previous month, has forced security teams to make rapid triage decisions rather than following a standard monthly review cycle.

The most urgent issue to emerge from the release is CVE-2026-58644, a critical (CVSS 9.8) SharePoint Server vulnerability stemming from unsafe deserialization of untrusted data. The flaw allows an unauthenticated attacker to remotely execute arbitrary code against on-premises SharePoint Server deployments, including SharePoint 2016, 2019, and Subscription Edition. Although Microsoft’s advisory initially described exploitation as merely “more likely,” the company revised its guidance within a day of release to confirm the flaw was already being weaponized. CISA added CVE-2026-58644 to its Known Exploited Vulnerabilities catalog on July 16 and separately warned that it is being exploited alongside three other SharePoint flaws, CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, to gain unauthorized access to on-premises instances.

Researchers have drawn direct comparisons to last year’s “ToolShell” campaign, in which a chain of SharePoint deserialization bugs was used to conduct a mass exploitation campaign against internet-facing servers worldwide. CISA is urging organizations to enable Microsoft’s Antimalware Scan Interface across all SharePoint web applications, rotate A​S​P​.​N​E​T machine keys, and treat any internet-exposed, unpatched SharePoint instance as potentially compromised pending forensic review. The timing is especially unfavorable for organizations still running SharePoint Server 2016 or 2019, both of which reached the end of extended support on July 14, the same day the vulnerability was disclosed.

Security teams are being advised to prioritize SharePoint Server remediation above the rest of this month’s patch volume, apply Microsoft’s fixes on an emergency basis, and hunt for signs of persistence such as web shells or stolen IIS machine keys on any server that was internet-facing before patches were applied. The episode underscores a broader theme security researchers have flagged throughout 2026: as vulnerability disclosure volumes climb, the gap between patch release and mass exploitation continues to shrink, leaving defenders with an ever-narrower window to act.

Share

Related Posts

shubham-dhage-2nnRCNuHdVs-unsplash
8machine-_-pzcfw9AV5HY-unsplash
cphotos-qvvZJxbohtc-unsplash

Copyright © All Right Reserved

Privacy Policy