SharePoint out of support and already under attack: the window has closed

On 14 July 2026, Microsoft shipped the largest patch release in its history. The same day, SharePoint Server 2016 and 2019 dropped out of extended support — while SharePoint flaws were being actively exploited. Organisations still on those versions now face an ongoing attack and the permanent absence of fixes.
Two deadlines landing on the same day
The end-of-support dates are unambiguous in Microsoft's lifecycle records: extended support for SharePoint Server 2016 and SharePoint Server 2019 ended on 14 July 2026. There is no paid extension programme as there was for Windows: after that date, a flaw found in these versions stays open indefinitely.
On the same day, CISA warned about active exploitation of several vulnerabilities affecting on-premises SharePoint Server. Three were already being exploited, including CVE-2026-45659, a deserialisation remote code execution rated 8.8, patched out of band in late May 2026 and added to the US agency's known-exploited catalogue on 1 July. A fourth, CVE-2026-58644 — unauthenticated remote code execution rated 9.8 — was confirmed exploited the following day and catalogued on 16 July.
As things stand, neither CISA nor Microsoft has attributed these attacks to an identified actor. That detail matters: no attribution does not mean no risk, it means nobody yet knows who is striking, or why.
The detail every board should sit with
Vulnerability CVE-2026-45659 tells a story about a poorly understood mechanism. Microsoft initially rated it as unlikely to be exploited. It was patched in late May. It was confirmed exploited in early July. In between sat five weeks during which organisations that read "exploitation less likely" and deferred the update were exposed without knowing it.
The lesson is easy to state and hard to apply: a vendor rating is an estimate at a point in time, not permission to defer. The only defensible rhythm is a planned patch cycle, where the question is not "is this urgent?" but "when do we apply it, and who verifies that it landed?"
A patch volume that will not come back down
July's release is dizzying: by the Zero Day Initiative's count, 621 vulnerabilities fixed, 63 of them critical — a record, and a figure that already excludes some 480 Chromium and Edge patches for the month. Counts vary with the perimeter each analyst uses, but the order of magnitude is not in dispute.
Three were zero-day flaws: two actively exploited — a SharePoint privilege escalation and a privilege escalation in Active Directory Federation Services — and one publicly disclosed with no observed exploitation, a BitLocker bypass requiring physical access to the machine.
More importantly, Microsoft warns the volume will stay high: it attributes the inflation to bringing an AI-powered vulnerability discovery system into service. This is not an exceptional spike, it is the new normal. No organisation processes several hundred monthly patches by hand — which is exactly what makes a tooled, contractual process unavoidable, including for a modest-sized business.
If you are running an unsupported version
The rule is blunt but clear: a SharePoint 2016 or 2019 reachable from the internet should be treated as eventually compromised, not as at risk. No configuration compensates for the permanent absence of patches on an actively targeted platform.
Three paths, in order of preference: migrate to a supported version or to the online service; failing that, remove internet exposure immediately and allow access only over a VPN with multi-factor authentication; as a last resort, isolate the server and schedule its replacement with a date written down. The logic matches an end-of-life Windows estate: obsolescence is not a technical problem, it is a budget decision that was postponed.
And since remote code execution opens the door to your data being encrypted, check the last line of defence: immutable backups whose restoration has been tested and timed.
Action plan for the next ten days
- Inventory: do you run SharePoint on-premises, which version, and is it reachable from the internet?
- Apply the July patches on still-supported versions, without waiting for the usual maintenance window.
- Cut internet exposure on any unsupported instance — today rather than tomorrow.
- Hunt for post-exploitation traces: new accounts, scheduled tasks, files dropped in web directories.
- Extend the inventory to other unsupported software — there are almost always others.
- Set a written, budgeted exit date for every unsupported system identified.
- Formalise the patch cycle: frequency, owner, maximum delay for exploited flaws, proof of application.
- Test a full restoration and record the actual time achieved.
- Have your exposure reviewed by an outside eye if nobody owns it internally.
How SOVALYX can help
SOVALYX handles this kind of situation in two stages: a rapid inventory of what is exposed and out of support across your estate, then a costed exit plan — migrate, isolate or replace — with interim risk-reduction measures. We then run the patch cycle under SLA, with continuous monitoring and tested immutable backups, so the next critical fix no longer depends on one person being available.
Talk security with an engineer🧰 The companion tool: Would your backups survive a ransomware attack? — free · 2 minutes.
Reviewed and optimised by AI.