Three Days. That's the Federal Deadline for the SharePoint Bug That's Already Been Used to Break Into DHS.

Here's a timeline. Microsoft patches CVE-2026-58644 (unauthenticated remote code execution in SharePoint Server, CVSS 9.8) on July 14. CISA adds it to the Known Exploited Vulnerabilities catalog two days later, on July 16, and sets a federal remediation deadline of July 19. Three days, for a bug that scored a 9.8. CISA doesn't hand out three-day deadlines for hypothetical risk. It hands them out because the exploitation was already happening.

Now put that next to a second timeline that CISA also confirmed: three additional CVEs (2026-32201, 2026-45659, 2026-56164) chained together by attackers into a full path from spoofed requests to remote code execution to privilege escalation, with a payoff of stolen IIS machine keys. Read that last part again. Machine keys. Once an attacker has them, they can forge authenticated requests on your SharePoint instance indefinitely, and your patch cycle has nothing to say about it, because the keys were already out the door before you applied the fix. CISA's guidance on this is unambiguous: cleanup means threat hunting and key rotation, not just confirming the patch installed. If your remediation checklist stops at "patched," you have not remediated anything. You've updated the version number on a compromise that's still running.

This is not a hypothetical for a security-conference slide. The Department of Homeland Security confirmed on July 1 that its own Homeland Security Information Network (the platform coordinating threat intelligence and event-security planning across federal, state, local, and international partners) was breached between late May and early June, with SharePoint among the systems attackers touched, during the operational runway for World Cup security work. DHS says classified systems weren't reached and hasn't confirmed what, if anything, was actually taken. Fine. Sit with what wasn't classified anyway: the channel agencies use to coordinate who's watching what, during a major international event, run on the same collaboration platform that just handed attackers a documented path to persistence that survives patching.

If you administer SharePoint on-prem, you already know what CISA is asking for: patch, yes, but also rotate the machine keys and hunt for persistence mechanisms that predate the patch. Skip the second half and you've solved a CVSS score, not an intrusion. The difference between those two things is exactly the difference between "compliant" and "still compromised," and right now a federal agency's own information-sharing backbone is the live example of what happens when that difference gets missed.

What's your organization's actual remediation checklist look like for a CVE this severe, patch and move on, or patch and go hunting? Say so in the comments. This is exactly the gap attackers are counting on you to skip.