CVE-2026-58644
Published Jul 14, 2026
Last updated a month ago
AI description
CVE-2026-58644 is a vulnerability found in Microsoft Office SharePoint, categorized as a deserialization of untrusted data flaw. This vulnerability enables an unauthorized attacker to execute code over a network. The flaw affects multiple versions of Microsoft SharePoint Server, including Subscription Edition, 2019, and 2016. The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-58644 to its Known Exploited Vulnerabilities Catalog, indicating that it is being actively exploited.
- Description
- Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
- Products
- sharepoint_server
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
- Exploit added on
- Jul 16, 2026
- Exploit action due
- Jul 19, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- secure@microsoft.com
- CWE-502
- Hype score
- Not currently trending
⚡️ August "In the Trend of VM" (#30): 4 trending vulns - ViPNet Client RCE (BDU:2026-09885), Windows Kernel EoP (CVE-2026-42980), and 2 actively exploited SharePoint flaws (CVE-2026-56164, CVE-2026-58644). #TrendVulns #ViPNet #Windows #SharePoint ➡️ https://t.co/NAraJjJJU
@leonov_av
17 Aug 2026
65 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Recent SharePoint CVEs (2026) CVE-2026-45659: A high-severity remote code execution flaw affecting on-premises SharePoint Server. It allows authenticated users with basic access to run code, and CISA confirmed active ransomware exploitation. CVE-2026-58644: A critical (CVSS ht
@FosoTweets
12 Aug 2026
102 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV. CISA says SharePoint CVE-2026-58644 was exploited before Microsoft patched it, affecting all supported on-premises versions and enabling RCE. https://t.co/jsc8Mc4914
@wilwj38529146
24 Jul 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Still seeing substantial amounts of Microsoft SharePoint unpatched instances that have been added to @CISACyber Known Exploited Vulnerability catalog last few weeks. This includes CVE-2026-50522, CVE-2026-56164, CVE-2026-58644 with 878 IPs (1585 FQDNs) unpatched on 2026-07-23 ht
@Shadowserver
24 Jul 2026
1704 Impressions
6 Retweets
15 Likes
5 Bookmarks
1 Reply
0 Quotes
Microsoft July Patch Tuesday: 622 CVEs, the largest release in company history, with 2 actively exploited zero-days. CVE-2026-58644 (SharePoint RCE, CVSS 9.8) and CVE-2026-56155 (AD FS priv esc) now on CISA KEV. Patch now. #InfoSec #ZeroDay #PatchTuesday
@infrasecserv
22 Jul 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoftの2026年7月の月例更新は、同社製品のCVEを627件(リリースノート見出しの件数。製品別表の合計は622件)扱い、別枠でMicrosoft製ではないChromiumのCVEを428件再公開しています。悪用確認済みは3件で、うちSh
@MalwareBibleJP
19 Jul 2026
1068 Impressions
1 Retweet
2 Likes
2 Bookmarks
0 Replies
0 Quotes
🔐 Daily Security & Standards Brief (Jul 19) CVE-2026-58644 — Microsoft SharePoint: patch Microsoft SharePoint and validate deserialization bounds. Full digest 👇 — PCMedicalist Full digest 👇 via PCMedicalist #CyberSecurity #InfoSec https://t.co/3FmOzpYB6N
@PCMedicalist
19 Jul 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-58644: Microsoft SharePoint Server Unauthenticated RCE — Detection and… "A critical security vulnerability, CVE-2026-58644, has been identified in Microsoft SharePoint…" 🔗 https://t.co/k084WOpFSE #CyberSecurity #ThreatIntel #critical #zer
@SecurityAr58409
19 Jul 2026
51 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Today's #CTI brief for 2026-07-18: The dangerous systems are still being filed under "internal collaboration" and "security tooling," right up to the point they become a foothold. SharePoint CVE-2026-58644 and FortiSandbox CVE-2026-25089/CVE-2026-39808 have a July 19 federal
@alphahunt_io
18 Jul 2026
45 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨 Two critical vulnerabilities in on-premises Microsoft Office SharePoint Server allow RCE without authentication: CVE-2026-58644 and CVE-2026-50522. ▪️ Affected versions: on-premises editions of Microsoft SharePoint Server: SharePoint Server 2016, SharePoint Server 2019,
@censysio
17 Jul 2026
2708 Impressions
8 Retweets
32 Likes
16 Bookmarks
1 Reply
1 Quote
🔴 ALERTĂ: Vulnerabilități critice în Microsoft SharePoint. CVE-2026-50522 și CVE-2026-58644 (CVSS 9.8) permit execuție de cod la distanță. CVE-2026-58644 este exploatată activ. Detalii: https://t.co/9aM8F68MVH #DNSC #CyberSecurity #SharePoint https://t.co/QguYaw5A9d
@DNSC_RO
17 Jul 2026
222 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA adds actively exploited vulnerabilities to KEV: • CVE-2026-39808 & CVE-2026-25089 – Fortinet FortiSandbox (Critical) • CVE-2026-58644 – Microsoft SharePoint (CVSS 9.8) Federal agencies must patch by July 19. Prioritize these updates. #CISA #Vulnerability #Patc
@ThreatByte
17 Jul 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Four on-premises SharePoint Server CVEs are actively exploited: CVE-2026-32201 (CVSS 6.5), CVE-2026-45659 (CVSS 8.8), CVE-2026-56164 (CVSS 9.8), and CVE-2026-58644 (CVSS 9.8). #DFIR_Radar https://t.co/ln2QdK28Q8
@DFIR_Radar
17 Jul 2026
190 Impressions
0 Retweets
1 Like
1 Bookmark
2 Replies
0 Quotes
CISA KEV catalog adds three actively exploited flaws: FortiSandbox CVE-2026-25089, CVE-2026-39808, and SharePoint CVE-2026-58644. Patch by July 19. #CISA #KEV #Fortinet #FortiSandbox #SharePoint #CVE202658644 #ActivelyExploited #CyberSecurity https://t.co/piHbyDae7Q
@Daily_CyberSec
17 Jul 2026
350 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🔐 Daily Security & Standards Brief (Jul 17) • CVE-2026-58644 — Microsoft SharePoint Deserialization of Untrusted Data Vulnerability — CISA KEV Vulns → track CVE-2026-58644 and patch Microsoft SharePoint Deserialization of Untru… Full digest 👇 via PCMedicalis
@PCMedicalist
17 Jul 2026
23 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
【常連】米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログにFortiSandboxのCVE-2026-25089及びCVE-2026-39808、並びにSharePointのCVE-2026-58644を追加。対処期限はいずれも3日語の7/19。
@__kokumoto
16 Jul 2026
756 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
🚨 CRITICAL: CVE-2026-58644 - Microsoft SharePoint deserialization flaw (CISA KEV). Unauthorized remote code execution possible. Patch by July 19, 2026. #CVE #PatchNow #ThreatIntel https://t.co/s9HnQljfYf
@DFIR_Lab
16 Jul 2026
48 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️We added Fortinet FortiSandbox vulnerabilities CVE-2026-25089 & CVE-2026-39808 and Microsoft SharePoint vulnerability CVE-2026-58644 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec
@CISACyber
16 Jul 2026
6150 Impressions
7 Retweets
29 Likes
3 Bookmarks
2 Replies
1 Quote
CVE-2026-58644: SharePoint Server deserialization RCE (CVSS 9.8). Unauthenticated, network-exploitable. Sibling CVE demoed at Pwn2Own Berlin. Same July 14 patches as KEV-listed CVE-2026-56164. Investigation workflow → https://t.co/XV8bU4m3Ph
@hellorecon
15 Jul 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Running SharePoint? There are at least 4 vulns you want to pay attention to: CVE-2026-55040, CVE-2026-52522, CVE-2026-58644, CVE-2026-56164 unauthenticated RCE, exploits available etc. https://t.co/9moTd0gNju
@theluemmel
15 Jul 2026
2063 Impressions
2 Retweets
16 Likes
8 Bookmarks
2 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-58644: Microsoft SharePoint Deserialization RCE — Detection and Harden… "CVE-2026-58644 represents a significant escalation in risk for enterprises relying on…" 🔗 https://t.co/vl0JucLagR #CyberSecurity #ThreatIntel #cve202658644 #critical
@SecurityAr58409
15 Jul 2026
46 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*",
"matchCriteriaId": "5FA63EA8-B225-4E35-A6A3-DBDECF5AC4C8",
"versionEndExcluding": "16.0.19725.20434",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "F815EF1D-7B60-47BE-9AC2-2548F99F10E4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*",
"matchCriteriaId": "6122D014-5BF1-4AF4-8B4D-80205ED7785E",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]