Arctic Wolf Security Bulletin
Arctic Wolf Security Bulletin

UPDATE: Microsoft SharePoint Server Vulnerabilities – Immediate Patching Required

Arctic Wolf Security Bulletin
6 min read

Threat Summary

Cybersecurity and Infrastructure Security Agency (CISA) has added several critical zero-day vulnerabilities targeting Microsoft SharePoint Server. CVE-2026-58644 is a deserialization flaw in SharePoint Server (Subscription Edition <16.0.19725.20434; 2019 <16.0.10417.20175; 2016 <16.0.5561.1001) that allows remote, authenticated attackers to execute arbitrary code, gain persistence (historically through IIS machine key theft), and establish footholds in enterprise environments.

CVE-2026-50522 is a critical SharePoint Server deserialization remote code execution vulnerability with a CVSS score of 9.8. Public proof-of-concept exploit code for CVE-2026-50522 became available shortly after Microsoft’s July 2026 emergency patches, contributing to rapid and widespread exploitation. Attackers can deliver malicious .NET deserialization payloads through vulnerable SharePoint endpoints to execute arbitrary code, steal IIS machine keys for persistence, and facilitate credential or token theft.

CISA added CVE-2026-58644 to its Known Exploited Vulnerabilities (KEV) catalog on July 16, 2026, with a strict remediation deadline (July 19, 2026) for federal agencies. As of this writing, no public proof-of-concept exploits exist for the SharePoint CVE-2026-58644. Public PoC code is available for CVE-2026-50522 and exploitation of that issue has been observed globally against on-premises SharePoint Server deployments. SharePoint Online is not affected.

Affected sectors include U.S. government, enterprise, financial, healthcare, and any organization operating on-premises SharePoint. The zero-day window is extremely short, organizations had at most 5 days from disclosure to mandatory patching. The risk includes system takeover, data exfiltration, lateral movement, and deployment of ransomware or spyware. The current threat landscape is critical: patching and additional layered defenses are essential to halt ongoing campaigns.

Recommendations

Immediate Actions (Highest Priority):

  • Patch all affected Microsoft SharePoint Servers to the most recent cumulative updates:
  • Subscription Edition: KB5002882 (≥16.0.19725.20434)
  • 2019: KB5002883/KB5002885 (≥16.0.10417.20175)
  • 2016: KB5002891/KB5002892 (≥16.0.5561.1001)
  • For any installations that cannot be patched immediately, remove public internet exposure (apply network segmentation, firewall rules, or take offline).
  • Rotate http://ASP.NET machine keys and restart IIS after patching SharePoint, to invalidate any previously stolen credentials or abused sessions.
  • After patching use Microsoft-supported machine key rotation steps such as Set-SPMachineKey and Update-SPMachineKey, then restart IIS on all SharePoint servers. Because CVE-2026-50522 exploitation may enable theft of machine keys and credentials, also change passwords for SharePoint and IIS service accounts and review account privileges.

Configuration and Hardening:

  • Enable AMSI (Antimalware Scan Interface) Full Mode and Defender AV on all SharePoint servers.
  • Audit and restrict Site Owner and administrator privileges, enforce MFA and minimum-necessary access, especially for Central Admin and internet-facing interfaces.

Long-Term Protection:

  • Decommission or isolate end-of-life / unsupported SharePoint installations from all internet interface.
  • Continuously apply critical security updates on release and follow vendor/industry advisories.
  • Regularly review configuration and perform privileged access management on all sensitive applications.

Temporary Workarounds

  • If immediate patching is impossible, block HTTP(S) access to vulnerable servers from the public internet and isolate systems within internal-only networks until updates are applied.
  • Consider disabling unused SharePoint endpoints temporarily, but beware this provides limited protection as the vulnerability affects key server-side code pathways.
  • Monitor for new admin accounts or anomalous activity and prepare to reset/rotate all potentially compromised credentials and keys.
  • Workarounds do not eliminate risk. Full patching is the only reliable mitigation. Workarounds are temporary and do not address all exploit vectors.

References

Share this post: