Skip to content
arrow-alt-circle-up icon

Cyber Incident?

arrow-alt-circle-up icon

Call 00800 1744 0000

arrow-alt-circle-up icon

See all Threat Responses

Dutch follows English

Microsoft has released critical security updates for Office and SharePoint products as part of Patch Tuesday on the 14th of July 2026. One vulnerability in SharePoint (CVE-2026-58644) is already being actively exploited by attackers. We are sending out this threat response now following reporting from the NCSC on widespread abuse of SharePoint vulnerabilities, and immediate action is required to protect your systems [1][2][3].

Description
Multiple security vulnerabilities have been discovered in Microsoft Office products including Word, Excel, PowerPoint, and SharePoint [1][4]. This threat response focuses on CVE-2026-58644, a critical remote code execution vulnerability in on-premises SharePoint Server. The vulnerability is caused by unsafe deserialization of untrusted data and may allow an unauthenticated attacker to send a specially crafted network request to a vulnerable SharePoint server and execute arbitrary code. SharePoint servers are sometimes reachable from the internet for collaboration, extranet, or remote-access purposes, which makes exposed and unpatched servers a high-priority target. CVE-2026-58644 affects SharePoint servers and has a severity score of 9.8 out of 10. This vulnerability was exploited by attackers before Microsoft could release a patch (known as a "zero-day" attack) [1][2][3]. Additional vulnerabilities affect other Office applications and can allow attackers to gain elevated access to your systems or execute malicious code [1][4].

Impact
We estimate the impact of these vulnerabilities as HIGH.

If exploited, these vulnerabilities allow attackers to:

  • Execute malicious software on your SharePoint servers without any user interaction [1][2]
  • Take complete control of affected systems [1][2]
  • Steal sensitive business information and documents [1]
  • Move laterally through your network to compromise additional systems [2]
  • Disrupt business operations and cause financial damage [1]
  • Impersonate legitimate users within your organization [1]

The SharePoint vulnerability is particularly dangerous because attackers can exploit it remotely without requiring any employee to click a link or open a file [1][2].

Risk
We estimate the risk of these vulnerabilities as HIGH.

The Dutch National Cyber Security Centre (NCSC-NL) has classified both the likelihood of exploitation and potential damage as HIGH [1]. The SharePoint vulnerability is already being actively exploited in the wild, meaning attackers are successfully using it right now [1][3]. Microsoft Office and SharePoint are used extensively across nearly all organizations, making these vulnerabilities widely applicable. The combination of active exploitation, critical severity, and widespread product deployment creates an immediate and serious risk to your environment [1][2][3].

Mitigation
Microsoft has released security updates that fix these vulnerabilities. Install all available updates for Microsoft Office products and SharePoint as quickly as possible. Prioritize updating any SharePoint servers that are accessible from the internet, as these face the highest risk of exploitation [1][2][4].

The updates can be obtained through:

  • Windows Update for desktop Office applications [4]
  • Microsoft Update Catalog for server products [4]
  • Your organization's patch management system

Detailed update information is available at: https://portal.msrc.microsoft.com/en-us/security-guidance [2].

Ensure your SharePoint servers are updated to the versions listed below:

  • SharePoint Enterprise Server 2016: update to build 16.0.5556.1005 or later.
  • SharePoint Server 2019: update to build 16.0.10417.20153 or later.
  • SharePoint Server Subscription Edition: update to build 16.0.19725.20384 or later.

What should you do?
Take the following actions immediately:

  • Install security updates for all Microsoft Office products and SharePoint servers as soon as possible [1][4]
  • Prioritize SharePoint servers, especially those accessible from the internet [1][2]
  • Verify successful installation of updates across all systems
  • Contact your IT service provider if you need assistance identifying affected systems or deploying updates [1]
  • Monitor your systems for any signs of unusual activity or compromise [3]

If you are unsure whether your organization uses vulnerable versions of these products, contact your IT department or service provider immediately [1].

What will Northwave do?
We will monitor any developments regarding this vulnerability. If new critical information about this threat arises we will reach out to you. You can contact us by phone or send us an email if you would like additional information.

 


E-mail: soc@northwave-cybersecurity.com
Do you have an incident right now? Call our Incident Response Team: 00800 1744 0000

Disclaimer applies, see below.

References

[1] https://www.ncsc.nl/alerts/installeer-updates-voor-kwetsbaarheden-in-microsoft-office
[2] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644
[3] https://www.cisa.gov/news-events/alerts/2026/07/16/cisa-adds-three-known-exploited-vulnerabilities-catalog
[4] https://support.microsoft.com/en-us/servicing/office/update/2026/5105810

 

Microsoft heeft kritieke beveiligingsupdates uitgebracht voor Office- en SharePoint-producten als onderdeel van Patch Tuesday op 14 juli 2026. Eén kwetsbaarheid in SharePoint (CVE-2026-58644) wordt al actief uitgebuit door aanvallers. Wij versturen deze threat response nu naar aanleiding van berichtgeving van het NCSC over grootschalig misbruik van SharePoint-kwetsbaarheden. Onmiddellijke actie is vereist om uw systemen te beschermen [1][2][3].

Beschrijving
Er zijn meerdere beveiligingskwetsbaarheden ontdekt in Microsoft Office-producten, waaronder Word, Excel, PowerPoint en SharePoint [1][4]. Deze threat response richt zich op CVE-2026-58644, een kritieke kwetsbaarheid voor remote code execution in on-premises SharePoint Server. De kwetsbaarheid wordt veroorzaakt door onveilige deserialisatie van niet-vertrouwde gegevens en kan een niet-geauthenticeerde aanvaller in staat stellen om via een speciaal geprepareerd netwerkverzoek willekeurige code uit te voeren op een kwetsbare SharePoint-server. SharePoint-servers zijn soms vanaf het internet bereikbaar voor samenwerking, extranet- of remote-accessdoeleinden, waardoor blootgestelde en niet-gepatchte servers een doelwit met hoge prioriteit zijn. CVE-2026-58644 treft SharePoint-servers en heeft een ernstscore van 9,8 op 10. Deze kwetsbaarheid werd door aanvallers uitgebuit voordat Microsoft een patch kon uitbrengen (een zogenoemde “zero-day”-aanval) [1][2][3]. Aanvullende kwetsbaarheden treffen andere Office-applicaties en kunnen aanvallers in staat stellen verhoogde toegang tot uw systemen te verkrijgen of kwaadaardige code uit te voeren [1][4].

Impact
Wij schatten de impact van deze kwetsbaarheden in als HOOG.

Als deze kwetsbaarheden worden uitgebuit, kunnen aanvallers:

  • Kwaadaardige software uitvoeren op uw SharePoint-servers zonder enige gebruikersinteractie [1][2]
  • Volledige controle over getroffen systemen overnemen [1][2]
  • Gevoelige bedrijfsinformatie en documenten stelen [1]
  • Zich lateraal door uw netwerk verplaatsen om aanvullende systemen te compromitteren [2]
  • Bedrijfsactiviteiten verstoren en financiële schade veroorzaken [1]
  • Zich voordoen als legitieme gebruikers binnen uw organisatie [1]

De SharePoint-kwetsbaarheid is bijzonder gevaarlijk omdat aanvallers deze op afstand kunnen uitbuiten zonder dat een medewerker op een link hoeft te klikken of een bestand hoeft te openen [1][2].

Risico
Wij schatten het risico van deze kwetsbaarheden in als HOOG.

Het Nationaal Cyber Security Centrum (NCSC-NL) heeft zowel de kans op uitbuiting als de potentiële schade geclassificeerd als HOOG [1]. De SharePoint-kwetsbaarheid wordt al actief in het wild uitgebuit, wat betekent dat aanvallers deze op dit moment succesvol gebruiken [1][3]. Microsoft Office en SharePoint worden uitgebreid gebruikt binnen vrijwel alle organisaties, waardoor deze kwetsbaarheden breed toepasbaar zijn. De combinatie van actieve uitbuiting, kritieke ernst en brede inzet van de producten zorgt voor een onmiddellijk en ernstig risico voor uw omgeving [1][2][3].

Mitigatie
Microsoft heeft beveiligingsupdates uitgebracht die deze kwetsbaarheden verhelpen. Installeer alle beschikbare updates voor Microsoft Office-producten en SharePoint zo snel mogelijk. Geef prioriteit aan het updaten van SharePoint-servers die vanaf het internet bereikbaar zijn, omdat deze het grootste risico op uitbuiting lopen [1][2][4].

De updates kunnen worden verkregen via:

  • Windows Update voor desktopversies van Office-applicaties [4]
  • Microsoft Update Catalog voor serverproducten [4]
  • Het patchmanagementsysteem van uw organisatie

Gedetailleerde update-informatie is beschikbaar op: https://portal.msrc.microsoft.com/en-us/security-guidance [2].

Zorg ervoor dat uw SharePoint-servers zijn bijgewerkt naar de onderstaande versies:

  • SharePoint Enterprise Server 2016: update naar build 16.0.5556.1005 of nieuwer.
  • SharePoint Server 2019: update naar build 16.0.10417.20153 of nieuwer.
  • SharePoint Server Subscription Edition: update naar build 16.0.19725.20384 of nieuwer.

Wat moet u doen?
Neem onmiddellijk de volgende maatregelen:

  • Installeer zo snel mogelijk beveiligingsupdates voor alle Microsoft Office-producten en SharePoint-servers [1][4]
  • Geef prioriteit aan SharePoint-servers, vooral servers die vanaf het internet bereikbaar zijn [1][2]
  • Controleer of de updates succesvol op alle systemen zijn geïnstalleerd
  • Neem contact op met uw IT-dienstverlener als u hulp nodig heeft bij het identificeren van getroffen systemen of het uitrollen van updates [1]
  • Monitor uw systemen op tekenen van ongebruikelijke activiteit of compromittering [3]

Als u niet zeker weet of uw organisatie kwetsbare versies van deze producten gebruikt, neem dan onmiddellijk contact op met uw IT-afdeling of dienstverlener [1].

Wat doet Northwave?
Northwave houdt de ontwikkelingen omtrent deze kwetsbaarheid in de gaten. Als er belangrijke nieuwe informatie omtrent deze dreiging bekend wordt, stellen wij u hiervan op de hoogte. Als u behoefte heeft aan extra informatie zijn we zowel telefonisch als via email bereikbaar.

 

E-mail: soc@northwave-cybersecurity.com
Heeft u op dit moment een incident? Bel ons Incident Response Team: 00800 1744 0000

Disclaimer is van toepassing, zie hieronder.

Bronnen

[1] https://www.ncsc.nl/alerts/installeer-updates-voor-kwetsbaarheden-in-microsoft-office
[2] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644
[3] https://www.cisa.gov/news-events/alerts/2026/07/16/cisa-adds-three-known-exploited-vulnerabilities-catalog
[4] https://support.microsoft.com/en-us/servicing/office/update/2026/5105810

 

Disclaimer

Northwave has made every effort to make this information accurate and reliable. However, the information provided is without warranty of any kind and its use is at the sole risk of the user. Northwave does not accept any responsibility or liability for the accuracy, content, completeness, legality or reliability of the information provided. We will not be liable for any loss or damage of whatever nature, direct or indirect, consequential or other, whether arising in contract, tort or otherwise, which may arise as a result of your use of, or inability to use, this information or any additional information provided by us in direct or indirect relation to the information provided here.
.