Critical CVE-2026-58644, CVE-2026-50522, CVE-2026-65660, CVE-2026-55040, CVE-2026-56164, CVE-2026-45659 — Six on-premises SharePoint Server vulnerabilities have been exploited in the wild since July 2026, including unauthenticated remote code execution used by ransomware. Fixed build numbers for 2016, 2019 and Subscription Edition.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: If you run SharePoint Server on your own hardware (2016, 2019, or Subscription Edition) and it's reachable from the internet, it has been a top target all summer. Two bugs give unauthenticated remote code execution (CVSS 9.8), one is known to be used by ransomware, and CISA has added a new one roughly every few weeks. Install the latest SharePoint security update, rotate the machine keys, and check for web shells.
| Product | SharePoint Server 2016, 2019, Subscription Edition (on-premises). SharePoint Online / Microsoft 365 is not affected. |
|---|---|
| Worst bugs | CVE-2026-58644 and CVE-2026-50522: deserialization → RCE with no login, CVSS 9.8 |
| Also exploited | CVE-2026-55040 (auth bypass, 9.1), CVE-2026-65660 (code injection, 8.8), CVE-2026-45659 (deserialization, 8.8), CVE-2026-56164 (missing auth, 5.3) |
| Ransomware | CVE-2026-45659 is marked known ransomware use by CISA |
| Exploited? | Yes, all six on CISA KEV between 2026-07-01 and 2026-09-25 |
| Fix | Latest SharePoint cumulative/security update. Builds below. |
On-premises SharePoint has had a rough 2026. Between July and late September, CISA added six SharePoint Server CVEs to its Known Exploited Vulnerabilities list:
| CVE | Type | Login needed? | CVSS | KEV added |
|---|---|---|---|---|
| CVE-2026-45659 | Deserialization → RCE (ransomware) | Yes | 8.8 | 2026-07-01 |
| CVE-2026-56164 | Missing authentication → elevation of privilege | No | 5.3 | 2026-07-14 |
| CVE-2026-58644 | Deserialization → RCE | No | 9.8 | 2026-07-16 |
| CVE-2026-50522 | Deserialization → RCE | No | 9.8 | 2026-07-22 |
| CVE-2026-55040 | Weak authentication → security bypass | No | 9.1 | 2026-08-18 |
| CVE-2026-65660 | Code injection → RCE | Yes | 8.8 | 2026-09-25 |
“Deserialization of untrusted data” means SharePoint rebuilds objects from data an attacker sends, and a crafted payload makes it run code as the SharePoint service. The bugs that need a login are often paired with an auth-bypass bug in the same batch, so attackers don’t need valid accounts.
Only on-premises SharePoint Server is affected. If your documents live in SharePoint Online / Microsoft 365, Microsoft patches it for you.
On a SharePoint server, check the farm build in Central Administration → Upgrade and Migration → Check product and patch installation status, or in the SharePoint Management Shell:
(Get-SPFarm).BuildVersion
To be covered for all six CVEs you need at least:
| Version | Minimum build |
|---|---|
| SharePoint Server Subscription Edition | 16.0.19725.20522 |
| SharePoint Server 2019 | 16.0.10417.20198 |
| SharePoint Enterprise Server 2016 | 16.0.5565.1001 |
SharePoint 2013 and older are out of support and get no fixes at all. If you still run one, it needs to come off the internet now.
PSConfig.exe -cmd upgrade -inplace b2b -wait) to finish the upgrade.Update-SPMachineKey then Set-SPMachineKey, and restart IIS). Deserialization attacks commonly steal these keys, and a stolen key keeps working after the patch..aspx files in the SharePoint LAYOUTS folders (under C:\Program Files\Common Files\microsoft shared\Web Server Extensions\). Web shells there are the classic sign./_layouts/ pages from unfamiliar IPs, especially without an authenticated user.w3wp.exe spawning cmd.exe or powershell.exe in your EDR or Sysmon data.Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.