If your business runs its own SharePoint server, or has staff who manage one for a client or head office, there’s an urgent patch you need to know about. A critical vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-58644, has been added to the US government’s Known Exploited Vulnerabilities catalog after being actively used by attackers in the wild. With a severity score of 9.8 out of 10, this is about as serious as vulnerabilities get, and it’s a timely reminder for regional Victorian businesses about why patching matters even when you’re not a big enterprise target.
Microsoft SharePoint is widely used by businesses to store documents, manage internal wikis, and collaborate on files, either through a self-hosted server or as part of a Microsoft 365 setup. Researchers discovered a flaw in SharePoint Server that lets an attacker send specially crafted data to a vulnerable server and trick it into running malicious code, without needing a username or password. This is known as a remote code execution (RCE) vulnerability, and it’s about as bad as it sounds: an attacker who successfully exploits it can potentially take control of the server, access every file stored on it, and use it as a launching pad to attack the rest of your network.
What makes this particular flaw more urgent than most is that it was being exploited by attackers before Microsoft even had a patch ready, a scenario known as a zero-day attack. The US Cybersecurity and Infrastructure Security Agency (CISA), as reported by The Hacker News, has now formally listed it as a known exploited vulnerability, requiring US federal agencies to patch it immediately. While that mandate doesn’t apply to Australian businesses, it’s a strong signal that this is not a theoretical risk. If federal agencies are being told to drop everything and patch, that tells you real attacks are happening right now.
It’s easy to read a headline like this and assume it’s someone else’s problem; surely attackers are only interested in government departments or big city firms with deep pockets. That thinking is exactly what makes small and medium regional businesses attractive targets. Attackers running these campaigns often aren’t hand-picking victims: they use automated tools to scan the entire internet for servers running the vulnerable software, then attack whatever they find. A bakery in Bairnsdale running an old SharePoint server is just as visible to that scan as a bank in Melbourne.
Many regional businesses in Gippsland and across Victoria run their own on-premises servers for cost or historical reasons, sometimes set up years ago by an IT person who has since moved on, and rarely revisited since. These “set and forget” systems are exactly the kind of environment where a flaw like this can sit unpatched for months, quietly exposed to the internet, until someone finds it.
This is the first thing to check, because the answer changes what you need to do.
This incident is a useful case study in why prompt patching matters so much, even for small teams without a dedicated IT department. Vulnerabilities like this are discovered constantly, and the gap between a patch being released and attackers actively exploiting unpatched systems keeps shrinking. In this case, exploitation started before the fix was even publicly available, which means businesses that patch quickly once updates are released are still doing the right thing, but businesses that let updates pile up for weeks or months are effectively leaving the front door unlocked.
For a regional business without in-house IT staff, this often comes down to a simple structural question: who is responsible for checking and applying security updates across your servers, software, and devices? If the honest answer is “nobody, really” or “whoever remembers to”, that’s a gap worth closing before the next critical vulnerability appears, not after.
Vulnerabilities like this one will keep appearing, in SharePoint and in countless other systems businesses rely on every day. The businesses that weather these incidents without incident are rarely the ones with the biggest budgets, they’re simply the ones with a clear, reliable process for knowing what needs patching and getting it done quickly.
If you’re not sure whether your business is exposed to this kind of risk, Maximum IT Solutions offers a free security assessment for businesses across Gippsland and regional Victoria. We’ll review your current setup and flag anything that needs urgent attention — no obligation.
(+61) 0412 440 804