// Darksteel Insights · 2026-07-20
SMBs Urgently Need to Patch Critical SharePoint Vulnerability
A critical vulnerability in Microsoft SharePoint is being actively exploited. SMBs must act fast to protect their data.
- CVE-2026-58644 is a critical SharePoint vulnerability being actively exploited.
- SMBs using SharePoint should prioritize patching by July 19.
- Check if your SharePoint environment is exposed and update immediately.
- Perform a security review to detect if your system was already compromised.
What is CVE-2026-58644 and why is it dangerous?
CVE-2026-58644 is a critical vulnerability in Microsoft SharePoint that allows attackers to execute malicious code by exploiting how SharePoint processes untrusted data. This is known as a 'deserialization of untrusted data' flaw. In simple terms, the system is tricked into running code that it shouldn’t, potentially giving attackers full control.
This vulnerability is particularly dangerous because it can be exploited without user interaction. That means even if no one clicks on a suspicious link, a bad actor could still gain access to your system remotely.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed this flaw is already being used in attacks, which means it’s not just a theoretical threat—it’s actively being used to compromise systems.
Is this vulnerability a risk for small and mid-sized businesses?
Yes. If your business uses Microsoft SharePoint, especially in a public-facing or internal collaboration environment, you are at risk. SharePoint is commonly used by SMBs for document management, team collaboration, and intranet portals. If not patched, attackers could exploit this flaw to steal data, install malware, or even take over your network.
Even if you don’t actively use SharePoint, if it’s installed and accessible from the internet or internal networks, it could be a backdoor for attackers.
Because this vulnerability is being actively exploited, SMBs must treat it as a high-priority issue and act quickly to secure their systems.
What should SMBs do this week to protect themselves?
First, check if you’re using SharePoint and whether it’s exposed to the internet or internal users. If you are, apply the latest security patches from Microsoft as soon as possible. Microsoft has released updates to address this flaw, and CISA has set a hard deadline of July 19 for federal agencies to patch—SMBs should follow suit.
Next, disable any SharePoint features or services that aren’t necessary. Reducing the attack surface is a key security practice. If certain parts of SharePoint aren’t being used, turn them off and remove public access where possible.
Review your logs and look for any unusual activity, such as unexpected user logins, failed authentication attempts, or access to sensitive files. These could be signs that someone is already probing your system.
Finally, consider working with a cybersecurity provider to ensure your patching and configuration are correct. Many SMBs lack the in-house expertise to fully secure their SharePoint environments.
How can you tell if your system has already been compromised?
Detecting a breach can be tricky, but there are some signs to watch for. Unusual system behavior, such as unexpected restarts or performance slowdowns, could indicate an intrusion. Also, look for unauthorized user accounts or changes to system settings.
Review your SharePoint access logs for any suspicious activity, especially from unfamiliar IP addresses or during odd hours. If you see access attempts from known malicious IP ranges, that’s a red flag.
If you suspect a breach, isolate the affected system immediately and contact a cybersecurity expert to perform a forensic analysis. Don’t attempt to clean up the system yourself—this can destroy valuable evidence.
Not sure whether your environment is exposed? That is exactly what our Vulnerability Management service is built to surface. Talk to us.
Frequently asked questions
Is this vulnerability being used by ransomware groups?
Do I need to patch SharePoint if it’s not used by my company?
How long do I have to patch this flaw?
What if I don’t know if my company is using SharePoint?
Source (public domain): CISA