Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

SharePoint Server Under Attack: 6 Exploited CVEs in 2026 (CVE-2026-58644, 50522, 65660 and More)

Critical CVE-2026-58644, CVE-2026-50522, CVE-2026-65660, CVE-2026-55040, CVE-2026-56164, CVE-2026-45659 — Six on-premises SharePoint Server vulnerabilities have been exploited in the wild since July 2026, including unauthenticated remote code execution used by ransomware. Fixed build numbers for 2016, 2019 and Subscription Edition.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: If you run SharePoint Server on your own hardware (2016, 2019, or Subscription Edition) and it's reachable from the internet, it has been a top target all summer. Two bugs give unauthenticated remote code execution (CVSS 9.8), one is known to be used by ransomware, and CISA has added a new one roughly every few weeks. Install the latest SharePoint security update, rotate the machine keys, and check for web shells.

ProductSharePoint Server 2016, 2019, Subscription Edition (on-premises). SharePoint Online / Microsoft 365 is not affected.
Worst bugsCVE-2026-58644 and CVE-2026-50522: deserialization → RCE with no login, CVSS 9.8
Also exploitedCVE-2026-55040 (auth bypass, 9.1), CVE-2026-65660 (code injection, 8.8), CVE-2026-45659 (deserialization, 8.8), CVE-2026-56164 (missing auth, 5.3)
RansomwareCVE-2026-45659 is marked known ransomware use by CISA
Exploited?Yes, all six on CISA KEV between 2026-07-01 and 2026-09-25
FixLatest SharePoint cumulative/security update. Builds below.

What’s going on

On-premises SharePoint has had a rough 2026. Between July and late September, CISA added six SharePoint Server CVEs to its Known Exploited Vulnerabilities list:

CVETypeLogin needed?CVSSKEV added
CVE-2026-45659Deserialization → RCE (ransomware)Yes8.82026-07-01
CVE-2026-56164Missing authentication → elevation of privilegeNo5.32026-07-14
CVE-2026-58644Deserialization → RCENo9.82026-07-16
CVE-2026-50522Deserialization → RCENo9.82026-07-22
CVE-2026-55040Weak authentication → security bypassNo9.12026-08-18
CVE-2026-65660Code injection → RCEYes8.82026-09-25

“Deserialization of untrusted data” means SharePoint rebuilds objects from data an attacker sends, and a crafted payload makes it run code as the SharePoint service. The bugs that need a login are often paired with an auth-bypass bug in the same batch, so attackers don’t need valid accounts.

Am I affected?

Only on-premises SharePoint Server is affected. If your documents live in SharePoint Online / Microsoft 365, Microsoft patches it for you.

On a SharePoint server, check the farm build in Central Administration → Upgrade and Migration → Check product and patch installation status, or in the SharePoint Management Shell:

(Get-SPFarm).BuildVersion

To be covered for all six CVEs you need at least:

VersionMinimum build
SharePoint Server Subscription Edition16.0.19725.20522
SharePoint Server 201916.0.10417.20198
SharePoint Enterprise Server 201616.0.5565.1001

SharePoint 2013 and older are out of support and get no fixes at all. If you still run one, it needs to come off the internet now.

How to patch

  1. Install the latest SharePoint security update for your version (from Windows Update / Microsoft Update or the Microsoft Update Catalog) on every server in the farm.
  2. Run the SharePoint Products Configuration Wizard (or PSConfig.exe -cmd upgrade -inplace b2b -wait) to finish the upgrade.
  3. Rotate the ASP.NET machine keys after patching (Update-SPMachineKey then Set-SPMachineKey, and restart IIS). Deserialization attacks commonly steal these keys, and a stolen key keeps working after the patch.
  4. Confirm AMSI integration is on for each web application (it’s on by default in Subscription Edition and recent 2016/2019 updates) and that Defender or another AV is running on the servers.

If you can’t patch today

  • Take SharePoint off the internet. Put it behind a VPN or an authenticating reverse proxy so anonymous requests never reach it.
  • If external access is unavoidable, allowlist the IP ranges that need it.

Was I hit?

  • Look for new or recently changed .aspx files in the SharePoint LAYOUTS folders (under C:\Program Files\Common Files\microsoft shared\Web Server Extensions\). Web shells there are the classic sign.
  • Review IIS logs for POST requests to unusual /_layouts/ pages from unfamiliar IPs, especially without an authenticated user.
  • Look for w3wp.exe spawning cmd.exe or powershell.exe in your EDR or Sysmon data.
  • If you find anything, assume the machine keys and any credentials on the server are compromised. Rotate them and bring in incident response before ransomware follows.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories