Four SharePoint flaws joined CISA's exploited list in July

Microsoft SharePoint spent July as one of the most reliably attacked products on the internet. The US Cybersecurity and Infrastructure Security Agency added four separate SharePoint vulnerabilities to its Known Exploited Vulnerabilities catalog during the month, the list CISA maintains of flaws it has evidence are being used in real attacks. By IntelFusions' count that is twice as many SharePoint entries as the catalog took on in the whole of the first half of 2026.

The last of the four, CVE-2026-50522, went onto the list on 22 July and has drawn the least attention of the batch. CISA classes it as a deserialization of untrusted data issue and says it "could allow an unauthorized attacker to execute code over a network". The National Vulnerability Database scores it 9.8 out of 10, critical, in its record for the flaw.

Why this one stands out

EPSS, the community scoring model that estimates how likely a flaw is to see exploitation attempts in the next 30 days, currently puts CVE-2026-50522 at roughly 76 percent. That is far ahead of the other three July SharePoint entries, which sit at about 22 percent, 9 percent and 6 percent. A KEV listing already means exploitation has been observed, so the EPSS number is best read as a signal of how broad that activity is likely to get, not of whether it exists.

The other three are CVE-2026-45659, added on 1 July, which we covered when CISA first flagged it; CVE-2026-56164, a missing authentication issue rated 5.3 that landed on 14 July, the same day Microsoft shipped a 622 flaw Patch Tuesday; and CVE-2026-58644, another 9.8 deserialization bug added on 16 July.

What the catalog does and does not tell you

A KEV entry is deliberately thin: a CVE number, a short vulnerability class, a date and a remediation deadline. CISA does not publish affected build numbers, exploitation detail, or who is doing the exploiting, and neither the catalog nor the NVD record names a campaign or an actor behind CVE-2026-50522. Microsoft's own advisory for the CVE is where the affected versions and the update packages are listed, and that is the document to patch from. We are not going to guess at the rest, and neither should anyone planning a response.

One field the catalog does track is ransomware. None of the four July SharePoint entries is currently marked as known to be used in ransomware campaigns. That is a record of what CISA knows today rather than an assurance, and the field has been updated after the fact before.

What you should do

Patch on-premises SharePoint to the builds Microsoft lists in each advisory, and treat all four CVEs as one job rather than four. Federal civilian agencies are bound by Binding Operational Directive 22-01 to remediate KEV entries by the published due date. For everyone else, a listing is the clearest public signal available that a flaw is being used against real targets. If you cannot patch immediately, start with any SharePoint instance reachable from the internet, which is where a network reachable code execution flaw matters most. It is also worth confirming you do not have an on-premises SharePoint server you had forgotten about, because these installations tend to outlive the projects that stood them up.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions