SharePoint CVE-2026-58644 Post-KEV Deadline: NC SMB Plan

SharePoint on-prem CVE-2026-58644 (CVSS 9.8, exploited) KEV deadline passed July 19. NC SMB catch-up defense playbook. Call (336) 886-3282.

Cover Image for SharePoint CVE-2026-58644 Post-KEV Deadline: NC SMB Plan

TL;DR: Microsoft SharePoint on-premises CVE-2026-58644 is a CVSS 9.8 deserialization-of-untrusted-data remote code execution vulnerability that Microsoft patched in the July 14, 2026 Patch Tuesday, confirmed in-the-wild exploitation by July 15, and CISA added to the Known Exploited Vulnerabilities catalog on July 16 with a July 19, 2026 federal remediation deadline. It is the fourth SharePoint on-prem CVE in the July 2026 exploitation wave, alongside CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, and CISA has issued specific hardening guidance beyond just patching. The July 19 federal deadline has passed. For any NC SMB still running SharePoint Server 2016, 2019, or Subscription Edition on-premises, the operational meaning today (July 26) is: assume-compromise posture, deploy the patch, rotate MachineKeys, and begin an M365-migration conversation for 2026 Q4 or 2027 Q1.

Key takeaway: SharePoint on-premises is now a repeat-exploitation platform. Four unauthenticated or low-authentication RCE CVEs in a single month, three of them in CISA KEV, is not "patch and move on" — it is a signal that the on-prem SharePoint attack surface has aged past the practical operating cost for most NC SMBs. The right response is to (a) patch and rotate secrets now, (b) enable Antimalware Scan Interface (AMSI) integration and defender file scanning, (c) segment the SharePoint farm off any direct internet exposure, and (d) plan a controlled migration to SharePoint Online or a modern collaboration platform.

Need an emergency SharePoint patch, MachineKey rotation, and Microsoft 365 migration assessment? Contact Preferred Data Corporation at (336) 886-3282 for a two-week SharePoint security assessment. BBB A+ rated, serving High Point, Greensboro, Winston-Salem, Charlotte, Raleigh, and the Piedmont Triad since 1987.

What Is CVE-2026-58644 and Why Was the July 19 KEV Deadline Set So Aggressively?

CVE-2026-58644 is a CVSS 9.8 deserialization of untrusted data flaw in Microsoft SharePoint Server on-premises. Per Tenable's SharePoint CVE FAQ, the flaw allows an attacker authenticated at minimum as a Site Owner (a common role for external collaborators and third-party contractors) to write arbitrary code to the SharePoint server and execute it remotely.

  • Attack vector. Post-authentication as any Site Owner, so the effective attack surface includes every partner, vendor, or contractor account with any SharePoint site membership.
  • Patch status. Fixed in the Microsoft July 14, 2026 Patch Tuesday — the record-breaking 622-CVE release. Microsoft's advisory updated on July 15 to confirm exploitation-in-the-wild.
  • CISA KEV timeline. Added to the KEV catalog on July 16, 2026 with a July 19 federal remediation deadline — a three-day window under Binding Operational Directive 26-04 emergency-cadence rules.
  • Affected versions. SharePoint Enterprise Server 2016 (below build 16.0.5556.1005), SharePoint Server 2019 (below 16.0.10417.20153), and SharePoint Server Subscription Edition (below 16.0.19725.20384). SharePoint Online (Microsoft 365) is not affected.

The three-day federal deadline is a signal to the private sector. Cyber insurance underwriters and NC's regulated-industry auditors (medical, financial services, defense) are increasingly using CISA KEV timelines as the baseline for "reasonable diligence" — meaning a compromise attributable to an unpatched July 19 KEV deadline is now materially harder to defend in a claim or an audit.

Why Is This the Fourth SharePoint On-Prem RCE This Month?

July 2026 delivered a compressed sequence of four distinct SharePoint on-premises RCE flaws. CISA's July 14 hardening advisory explicitly names all four as areas of active exploitation.

  • CVE-2026-32201 — SharePoint on-prem authentication bypass (May 2026 patch cycle, actively exploited by early July)
  • CVE-2026-45659 — SharePoint on-prem RCE via deserialization (May 2026 patch, added to KEV early July with a July 4 federal deadline)
  • CVE-2026-56164 — SharePoint on-prem missing-authentication elevation of privilege (July 14 patch, added to KEV same day with a July 17 federal deadline)
  • CVE-2026-58644 — SharePoint on-prem RCE via deserialization (July 14 patch, added to KEV July 16 with July 19 federal deadline)

The pattern is the same underlying attack surface — SharePoint's .NET deserialization, ViewState handling, and MachineKey trust chain — being exploited through progressively different code paths. This is a signal about the maturity of the platform, not about a single bad patch. On-prem SharePoint's fundamental architecture predates modern zero-trust design principles by more than a decade.

Who in NC Is Still Running SharePoint On-Premises?

The SharePoint on-prem installed base in NC concentrates in five categories.

  • Law firms and litigation-support practices in Raleigh, Charlotte, and the Triad that use SharePoint on-prem as a matter-management/document-management platform, often paired with iManage or NetDocuments. On-prem is common for e-discovery hold reasons and for firms that pre-date the Microsoft 365 migration wave.
  • Manufacturers and defense contractors in the Piedmont Triad that use SharePoint for engineering document control, project sites, and ITAR/CUI staging. Some CMMC/DFARS deployments deliberately stay on-prem to control data-residency and access-review boundaries.
  • Regional healthcare organizations, hospital systems, and multi-provider medical groups using SharePoint for internal policies, procedures, credentialing, and clinician document sharing.
  • Municipal governments, county agencies, and community colleges across NC that standardized on SharePoint 2013/2016/2019 in the 2015-2020 window.
  • Family-owned distributors, dealerships, and construction/GC firms that use SharePoint for project sites, subcontractor document exchange, and internal knowledge base.

Any of these organizations still on SharePoint Server 2016 (which is out of mainstream support and receives only Security-Focused updates through 2026) faces a particularly acute decision this quarter: patch, harden, and hold, or migrate.

How Does This Sit Alongside Other July 2026 Emergency-Cadence CVEs?

The comparison shows why July 2026 became the "compressed federal-deadline" month. Every one of the following required patching inside 72 hours of KEV listing.

CVEProductCVSSKEV DateFederal DeadlineDays from Patch to KEV
CVE-2026-46817Oracle EBS Payments9.8Jul 15Jul 1848 days
CVE-2026-45659SharePoint on-prem RCE8.8Jul 1Jul 4~60 days
CVE-2026-56164SharePoint on-prem EoP8.8Jul 14Jul 170 days (same day as patch)
CVE-2026-58644SharePoint on-prem RCE9.8Jul 16Jul 192 days
CVE-2026-25089Fortinet FortiSandbox9.1Jul 16Jul 19Days
CVE-2026-39808Fortinet FortiSandbox9.1Jul 16Jul 19Days
CVE-2026-15409/15410SonicWall SMA100010.0/7.2Jul 15Jul 17Days

Three of four SharePoint CVEs went from patch to CISA KEV inside a week — a cadence that most NC SMB IT teams cannot match without either a mature internal patch program or a managed partner that runs KEV-triage on their behalf. Which is precisely why we've built PDC's KEV-triage service as an included component of our 24/7 managed IT and cybersecurity retainer.

What Should NC SMB SharePoint Operators Do This Week (Post-Deadline)?

Even though the federal deadline was July 19, the underlying risk continues. Six workstreams, run tightly.

  1. Confirm SharePoint version and deploy the July 14 patch. Compare farm build against the fixed builds (2016 ≥ 16.0.5556.1005, 2019 ≥ 16.0.10417.20153, Subscription Edition ≥ 16.0.19725.20384). Deploy the July CU tonight in a maintenance window; do not wait for a quarterly cycle.
  2. Rotate MachineKeys on all servers in the farm. The SharePoint deserialization attack chain exploits ViewState signing keys. Rotate MachineKeys per Microsoft's Update-SPMachineKey guidance and force an IISReset across the farm.
  3. Enable AMSI integration and defender-mode file scanning. Per CISA's SharePoint hardening advisory, enable AMSI on all SharePoint Web Application zones and confirm that Microsoft Defender (or your EDR) is actively scanning SharePoint web-front-end binaries and the TEMPLATE\LAYOUTS directory. Both were named exploitation staging areas in the July 2026 wave.
  4. Hunt for post-exploitation activity. Look for: (a) unusual w3wp.exe process trees spawning PowerShell or cmd.exe, (b) newly created .aspx files in LAYOUTS, _layouts, or bin directories, (c) inbound HTTP requests to /_layouts/15/toolpane.aspx, /_vti_bin, or Site Owner-privileged endpoints from unfamiliar IPs, (d) suspicious solution-package (.wsp) deployments.
  5. Segment the farm off direct internet exposure. No production SharePoint on-prem farm should be reachable directly from the public internet in 2026. Front with a WAF (Cloudflare, F5, Barracuda), or move access behind a VPN/ZTNA overlay. External-partner extranet sites should be re-hosted on Microsoft 365 or SharePoint Online with guest-access governance.
  6. Begin the migration conversation. Even if you patch and harden now, on-prem SharePoint's exploit cadence in 2026 is materially worse than Microsoft 365 SharePoint Online. Set a controlled migration target for Q4 2026 or Q1 2027; PDC can build the assessment and cutover plan.

What Are the Cyber Insurance and NC Compliance Consequences If You Miss the Patch Window?

Three intersections matter immediately.

  • Cyber insurance renewals. The 2026 renewal cycle now requires evidence-based attestation on KEV-cadence patching. A SharePoint compromise attributable to CVE-2026-58644 without a documented patch record inside the 72-hour KEV window creates a documentable pattern-of-neglect factor for insurers on both claim payout and next-year renewal pricing.
  • NC Identity Theft Protection Act. N.C.G.S. § 75-65 notification triggers if personal information of NC residents is compromised. SharePoint on-prem often holds employee PII, client contact data, and matter/case files that meet the threshold.
  • Regulated-industry contract obligations. HIPAA business-associate agreements, financial-services vendor MSAs, and DFARS 252.204-7012 contract clauses (for defense contractors) typically require notification within 24-72 hours of a security incident. The clock starts at discovery, not at breach.

The right posture right now, if you are behind on the July 19 KEV deadline: (1) patch tonight, (2) document the delay and mitigation for your insurance carrier, (3) rotate MachineKeys, (4) hunt for post-exploitation, and (5) put a written 2026-Q4 SharePoint Online migration on the strategic-plan agenda.

Ready for a two-week SharePoint compromise assessment and a right-sized Microsoft 365 migration plan for your NC business? Contact Preferred Data Corporation at (336) 886-3282. BBB A+ rated, serving the Piedmont Triad since 1987.

Frequently Asked Questions

Is SharePoint Online (Microsoft 365) affected by CVE-2026-58644?

No. CVE-2026-58644 affects on-premises SharePoint Server 2016, 2019, and Subscription Edition. Microsoft 365 SharePoint Online is a separate service and is not listed as affected. That is one of the reasons the migration case is strengthening: the on-prem product is bearing the exploitation burden the cloud service is not.

What if we're already past the July 19 deadline?

You are not alone — most NC SMBs are not on federal cadence. The catch-up sequence is: (1) patch tonight, (2) rotate MachineKeys, (3) enable AMSI + defender scanning, (4) hunt for post-exploitation, (5) document the delay for your cyber insurance carrier, and (6) start the M365 migration conversation. Do not skip step 4 — deserialization RCE typically leaves persistent web-shell artifacts in LAYOUTS or bin directories.

How do we know if we've been compromised?

Six indicators to check: (1) unfamiliar .aspx files with recent modified timestamps in LAYOUTS, _layouts/15, or bin directories, (2) w3wp.exe process trees spawning PowerShell, cmd.exe, or other interpreters, (3) inbound HTTP POST requests to Site-Owner-privileged endpoints from IPs you don't recognize, (4) new solution packages (.wsp) deployed outside your normal deploy pipeline, (5) authentication logs showing Site Owner logins from unusual geographies or IP ranges, (6) EDR alerts on SharePoint web-front-end servers that were downgraded, dismissed, or aged out.

Should we migrate to SharePoint Online now, or is patch-and-hold viable?

Both are valid, but the calculus has shifted. Four CVEs in a month, three in CISA KEV, is a signal that the on-prem exploit cadence in 2026 will continue to compress. For most NC SMBs, the total operational cost of patch-plus-rotate cycles is now within striking distance of the migration cost. PDC's usual recommendation: patch-and-hold for the next 60 days while you scope the migration, then target Q4 2026 or Q1 2027 for cutover.

Does SharePoint 2016 still receive security patches?

Yes, but on limited terms. SharePoint Server 2016 is out of mainstream support (ended July 2021) and out of extended support (ended July 2026 for most components) — verify against Microsoft's SharePoint 2016 lifecycle page. Even where security updates are still available under Extended Security Updates (ESU), the operational cost of running an EOL-adjacent collaboration platform in 2026 is high enough that most NC SMBs should treat SharePoint 2016 as end-of-life for planning purposes.

What NC-specific breach notification obligations apply to SharePoint incidents?

The NC Identity Theft Protection Act (N.C.G.S. § 75-65) requires notice to affected NC residents when personal information is compromised, and — for breaches over 1,000 residents — notice to the NC AG's Consumer Protection Division. Regulated industries (healthcare under HIPAA, financial services under GLBA, defense contractors under DFARS) have additional and often shorter clocks running from the point of discovery.

Support