Tech

SharePoint under attack: critical flaw exploited days after Patch Tuesday

Attackers wasted little time after Microsoft’s July Patch Tuesday, which fixed a record 622 vulnerabilities. One of them, CVE-2026-58644, is now being exploited in the wild. The bug scores a critical 9.8 on the CVSS scale and lets an authenticated attacker push executable code onto a server through unsafe deserialization. On-premises installations — SharePoint Server 2016, 2019 and the Subscription Edition — are affected, while SharePoint Online is not.

Microsoft initially listed the flaw as not exploited, but security firms spotted attacks shortly after disclosure. CISA has since added it to its Known Exploited Vulnerabilities catalog and gave US federal agencies just three days to patch. The nastier part: intruders are stealing IIS machine keys, which let them sign forged requests and keep a foothold long after the patch lands.

If you run SharePoint on your own iron, patch now, switch on AMSI integration and check the machine for signs of compromise. Rotate the keys only after cleanup — otherwise the attacker simply grabs the new ones as well.

Source: golem.de