Our takeMicrosoft's July 2026 bundle fixes 1164 CVEs including 3 already exploited in the wild (SharePoint CVE-2026-58644, two others). Patch those three out-of-band this week; the rest on your normal cycle. Lean-IT shops without SharePoint can largely ignore it; enterprises running on-prem SharePoint must treat the KEV trio as urgent.Cyber Resilience desk
Sources (11)
- msrc_patch · msrc_patch
- nvd_recent · nvd_recent
- cccs · cccs
- cisa_kev · cisa_kev
- hackernews · hackernews
- hackernews · hackernews
- bleeping · bleeping
- cisa_kev · cisa_kev
- cert_eu · cert_eu
- securityweek · securityweek
- helpnet · helpnet
What this means for you — Security leader:Patch out-of-band this week for CVE-2026-58644 (SharePoint, KEV, exploited) and the other two exploited CVEs; the remaining 24 Critical-rated fixes ride the normal patch cycle. SharePoint on-prem servers get priority — check CCCS AL26-017 for scope.
What this means for you — Lean IT orgs:If you run SharePoint on your own server (not the Microsoft 365 cloud version), patch it now — it's under active attack. If you use hosted Microsoft 365, this one doesn't apply to you; let Windows Update handle the rest on its normal schedule.
What this means for you — MSP:Inventory which clients run on-prem SharePoint Server versus SharePoint Online — only the former needs emergency action for CVE-2026-58644. Push the other three exploited CVEs (2026-56155, 2026-56164, 2026-48561) across the fleet this week; the rest of the 1164 can wait for standard rollout.
What this means for you — Researcher:CVE-2026-48561 (Copilot command injection, unauthenticated RCE over network) is worth watching independent of KEV status given the attack surface; CVE-2026-58644's deserialization root cause in SharePoint mirrors prior on-prem SharePoint RCE chains — worth comparing patch diffs.