Back to news

Microsoft Patches Record 570 Flaws; CISA Flags SharePoint Zero-Day

A historic Patch Tuesday and an actively exploited SharePoint RCE zero-day are forcing IT teams to prioritize remediation at unprecedented scale.

Microsoft Patches Record 570 Flaws; CISA Flags SharePoint Zero-Day

What happened

Microsoft released patches addressing 570 security vulnerabilities this cycle — nearly triple the previous record set just last month — with the company crediting AI-assisted discovery tools for the surge in identified flaws. Among the fixes is a critical SharePoint Server remote code execution vulnerability, tracked as CVE-2026-58644, carrying a CVSS score of 9.8. CISA moved swiftly to add the flaw to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. Federal civilian agencies have been ordered to apply the relevant patches no later than July 19, 2026.

Why it matters for your business

A CVSS score of 9.8 on a deserialization flaw means attackers can potentially execute arbitrary code on unpatched SharePoint instances with minimal friction — making this a priority regardless of whether an organization falls under CISA's federal mandate. The broader trend is equally significant: if AI tooling is now surfacing vulnerabilities at three times the historical rate, security and engineering teams should expect patch volumes of this magnitude to become routine rather than exceptional. Organizations relying on SharePoint for document management, intranets, or workflow automation face direct exposure until patched. The practical takeaway is to audit SharePoint Server versions immediately, validate patch deployment, and ensure vulnerability management workflows can scale to handle significantly larger patch loads going forward.

What to watch next

Security teams should monitor threat intelligence feeds for exploit code or ransomware groups weaponizing CVE-2026-58644, as actively exploited deserialization flaws historically attract opportunistic actors quickly. The role of AI in accelerating vulnerability discovery is also worth tracking — if Microsoft's disclosure rate continues to climb, vendor patch cadences and enterprise change management processes may need structural overhaul. Expect CISA to add further flaws from this release to the KEV catalog as active exploitation is confirmed in the coming weeks.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp