Microsoft SharePoint code execution flaw due July 17
| 9 added to KEV |
0 used in ransomware |
2026-07-17 nearest federal deadline |
Nine exploited vulnerabilities entered the federal patching deadline this week. One affects Microsoft SharePoint and requires immediate action to prevent network code execution.
The Showcase Vulnerability
CVE-2026-58644: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint contains a flaw that allows an unauthorized attacker to execute code over a network by exploiting unsafe deserialization of untrusted data. An attacker with network access can send a specially crafted request and gain arbitrary code execution on affected systems.
Required Action: Apply mitigations in accordance with Microsoft's vendor instructions. Evaluate each SharePoint deployment for internet exposure. If mitigations are unavailable, discontinue use of the product.
Due Date: July 19, 2026
Eight Other Exploited Vulnerabilities Added This Week
- Fortinet FortiSandbox OS Command Injection Vulnerability
- Fortinet FortiSandbox OS Command Injection Vulnerability
- Oracle E-Business Suite Improper Privilege Management Vulnerability
- KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
- Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
- Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
- SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- SonicWall SMA1000 Appliances Code Injection Vulnerability
The question now facing your security team: which of these nine vulnerabilities run in your environment, and which poses the greatest risk to fix first?
Struggling to patch before the deadline? We'll do this week's triage for you. Free.
Tell us what you run — we'll send back which of the currently-exploited vulnerabilities actually hit your stack, the order to fix them in, and what you can ignore. A person writes it, not a script. No call, no access to your systems.
Before you go — here's the 30-second version for your stack.
Everything CISA flagged this week fell into just a few buckets: 4 network & perimeter (Fortinet, SonicWall), 3 Microsoft & Windows (Microsoft), 1 enterprise apps (Oracle) and 1 other (KNX Association).
So if you don't run network & perimeter or Microsoft & Windows or enterprise apps or other, this week is a no-op for you. Close this email and get on with your day — nothing here is yours. If you do run one of them, the deadline is 2026-07-19.
That paragraph you just read — "this week is a no-op for you" — is the entire product. Most weeks, most of the catalog isn't yours. Knowing which part is, in 30 seconds, without reading a vulnerability database, is what you're actually short of.
ClickSecurity Pro does it precisely instead of roughly: you tell us your stack once, and each week you get only what touches your gear — ranked by what to fix first, with the fixed version and the federal deadline. No triage, no catalog, no guessing.
Filter next week to my stack — $5/mo
Not ready? Tell us what you run and we'll at least stop sending you things that aren't yours.