Critical SharePoint vulnerability now actively exploited

Just days after publication alongside Patch Tuesday, CVE-2026-58644 was added to CISA's Known Exploited Vulnerabilities catalogue. The flaw allows remote code execution in Microsoft SharePoint. Because it is exploitable over the network with low complexity, it carries a CVSS base score of 9.8, rated critical. All affected servers should be patched without delay.

What this means for you if you run SharePoint on-premises

If the SharePoint server runs on your own premises, this one lands on your desk. That is where the contracts, the board papers, the HR matters and the project documentation live. It is the material the organisation actually works on. Code execution on a server like that hands over the content and a foothold in the domain along with it. What matters most, in our assessment, is that the flaw is already being exploited, so time is not on your side.

We would stress that an on-premises SharePoint environment belongs to you and not to Microsoft. Nobody patches it for you. That is precisely the difference from a service Microsoft runs on your behalf, and the difference is the whole point of this story. Our view is that this is a job for today, not for the next operations meeting.

Berigo recommends

  • Patch every on-premises SharePoint server now, and confirm the update is genuinely in place on each one.
  • Remove internet exposure of SharePoint where there is no documented need for it.
  • Review the servers for signs of compromise from the publication date onward, not just from the point you patched.
  • Set a fixed remediation deadline for vulnerabilities on the CISA catalogue and track it in your management system.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch