Logo

Critical SharePoint Flaw: What Regional Businesses Need to Know

If your business runs its own SharePoint server, or has staff who manage one for a client or head office, there’s an urgent patch you need to know about. A critical vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-58644, has been added to the US government’s Known Exploited Vulnerabilities catalog after being actively used by attackers in the wild. With a severity score of 9.8 out of 10, this is about as serious as vulnerabilities get, and it’s a timely reminder for regional Victorian businesses about why patching matters even when you’re not a big enterprise target.

What Actually Happened

Microsoft SharePoint is widely used by businesses to store documents, manage internal wikis, and collaborate on files, either through a self-hosted server or as part of a Microsoft 365 setup. Researchers discovered a flaw in SharePoint Server that lets an attacker send specially crafted data to a vulnerable server and trick it into running malicious code, without needing a username or password. This is known as a remote code execution (RCE) vulnerability, and it’s about as bad as it sounds: an attacker who successfully exploits it can potentially take control of the server, access every file stored on it, and use it as a launching pad to attack the rest of your network.

What makes this particular flaw more urgent than most is that it was being exploited by attackers before Microsoft even had a patch ready, a scenario known as a zero-day attack. The US Cybersecurity and Infrastructure Security Agency (CISA), as reported by The Hacker News, has now formally listed it as a known exploited vulnerability, requiring US federal agencies to patch it immediately. While that mandate doesn’t apply to Australian businesses, it’s a strong signal that this is not a theoretical risk. If federal agencies are being told to drop everything and patch, that tells you real attacks are happening right now.

Why This Matters for a Regional Business, Not Just Big Corporates

It’s easy to read a headline like this and assume it’s someone else’s problem; surely attackers are only interested in government departments or big city firms with deep pockets. That thinking is exactly what makes small and medium regional businesses attractive targets. Attackers running these campaigns often aren’t hand-picking victims: they use automated tools to scan the entire internet for servers running the vulnerable software, then attack whatever they find. A bakery in Bairnsdale running an old SharePoint server is just as visible to that scan as a bank in Melbourne.

Many regional businesses in Gippsland and across Victoria run their own on-premises servers for cost or historical reasons, sometimes set up years ago by an IT person who has since moved on, and rarely revisited since. These “set and forget” systems are exactly the kind of environment where a flaw like this can sit unpatched for months, quietly exposed to the internet, until someone finds it.

Do You Actually Have SharePoint Server?

This is the first thing to check, because the answer changes what you need to do.

  • If your business uses Microsoft 365 and accesses SharePoint purely through a web browser or Teams, without a locally installed SharePoint Server, this specific vulnerability doesn’t directly apply to you. Microsoft manages the patching of the cloud service on your behalf.
  • If you or your IT provider have set up an on-premises SharePoint Server, whether that’s a dedicated server in a back office, a rack in a server room, or a virtual machine hosted somewhere, you need to confirm whether it’s patched.
  • If you’re not sure which applies to you, that uncertainty is itself a red flag worth resolving quickly.

What To Do If You Run SharePoint Server

  • Apply the Microsoft security update for CVE-2026-58644 immediately, don’t wait for a routine maintenance window.
  • Check whether your SharePoint server is exposed directly to the internet, or only accessible via internal network or VPN. Internet-facing servers are at much higher risk and should be prioritised.
  • Ask your IT provider to check server logs for signs of unusual activity, since this flaw has already been exploited by attackers before the patch existed.
  • Consider whether you still need an on-premises SharePoint server at all. Migrating to a cloud-hosted version through Microsoft 365 shifts a lot of this patching burden off your plate entirely.

The Bigger Lesson: Patching Is Not Optional

This incident is a useful case study in why prompt patching matters so much, even for small teams without a dedicated IT department. Vulnerabilities like this are discovered constantly, and the gap between a patch being released and attackers actively exploiting unpatched systems keeps shrinking. In this case, exploitation started before the fix was even publicly available, which means businesses that patch quickly once updates are released are still doing the right thing, but businesses that let updates pile up for weeks or months are effectively leaving the front door unlocked.

For a regional business without in-house IT staff, this often comes down to a simple structural question: who is responsible for checking and applying security updates across your servers, software, and devices? If the honest answer is “nobody, really” or “whoever remembers to”, that’s a gap worth closing before the next critical vulnerability appears, not after.

Practical Steps for Any Regional Business Owner

  • Make a simple list of every server and major piece of software your business runs, including who is responsible for keeping it updated.
  • Ask your current IT provider directly: “Are we currently exposed to any actively exploited vulnerabilities?” A good provider should be able to answer this without hesitation.
  • Set a policy that critical security patches, especially those flagged as actively exploited, get applied within days, not months.
  • Where practical, favour cloud-hosted versions of software like SharePoint over self-managed servers, since the patching responsibility shifts to the provider.
  • Keep a record of what systems face the internet directly, since these carry the highest risk and deserve the closest attention.

Vulnerabilities like this one will keep appearing, in SharePoint and in countless other systems businesses rely on every day. The businesses that weather these incidents without incident are rarely the ones with the biggest budgets, they’re simply the ones with a clear, reliable process for knowing what needs patching and getting it done quickly.


Worried This Could Affect Your Business?

If you’re not sure whether your business is exposed to this kind of risk, Maximum IT Solutions offers a free security assessment for businesses across Gippsland and regional Victoria. We’ll review your current setup and flag anything that needs urgent attention — no obligation.

Book your free security assessment →

Logo
Servicing small businesses across the valley.
Get in touch
Customer Support

(+61) 0412 440 804

Copyright © 2025 Maximum IT Solutions