CVE-2026-58644

Published Jul 14, 2026

Last updated a month ago

Exploit knownCVSS critical 9.8
Microsoft Office
Cloud
Zero-day
ICS
Server
Port (443)
SharePoint

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-58644 is a vulnerability found in Microsoft Office SharePoint, categorized as a deserialization of untrusted data flaw. This vulnerability enables an unauthorized attacker to execute code over a network. The flaw affects multiple versions of Microsoft SharePoint Server, including Subscription Edition, 2019, and 2016. The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-58644 to its Known Exploited Vulnerabilities Catalog, indicating that it is being actively exploited.

Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Source
secure@microsoft.com
NVD status
Analyzed
Products
sharepoint_server

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Exploit added on
Jul 16, 2026
Exploit action due
Jul 19, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

secure@microsoft.com
CWE-502

Social media

Hype score
Not currently trending
  1. ⚡️ August "In the Trend of VM" (#30): 4 trending vulns - ViPNet Client RCE (BDU:2026-09885), Windows Kernel EoP (CVE-2026-42980), and 2 actively exploited SharePoint flaws (CVE-2026-56164, CVE-2026-58644). #TrendVulns #ViPNet #Windows #SharePoint ➡️ https://t.co/NAraJjJJU

    @leonov_av

    17 Aug 2026

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Recent SharePoint CVEs (2026) CVE-2026-45659: A high-severity remote code execution flaw affecting on-premises SharePoint Server. It allows authenticated users with basic access to run code, and CISA confirmed active ransomware exploitation. CVE-2026-58644: A critical (CVSS ht

    @FosoTweets

    12 Aug 2026

    102 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV. CISA says SharePoint CVE-2026-58644 was exploited before Microsoft patched it, affecting all supported on-premises versions and enabling RCE. https://t.co/jsc8Mc4914

    @wilwj38529146

    24 Jul 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Still seeing substantial amounts of Microsoft SharePoint unpatched instances that have been added to @CISACyber Known Exploited Vulnerability catalog last few weeks. This includes CVE-2026-50522, CVE-2026-56164, CVE-2026-58644 with 878 IPs (1585 FQDNs) unpatched on 2026-07-23 ht

    @Shadowserver

    24 Jul 2026

    1704 Impressions

    6 Retweets

    15 Likes

    5 Bookmarks

    1 Reply

    0 Quotes

  5. Microsoft July Patch Tuesday: 622 CVEs, the largest release in company history, with 2 actively exploited zero-days. CVE-2026-58644 (SharePoint RCE, CVSS 9.8) and CVE-2026-56155 (AD FS priv esc) now on CISA KEV. Patch now. #InfoSec #ZeroDay #PatchTuesday

    @infrasecserv

    22 Jul 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Microsoftの2026年7月の月例更新は、同社製品のCVEを627件(リリースノート見出しの件数。製品別表の合計は622件)扱い、別枠でMicrosoft製ではないChromiumのCVEを428件再公開しています。悪用確認済みは3件で、うちSh

    @MalwareBibleJP

    19 Jul 2026

    1068 Impressions

    1 Retweet

    2 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  7. 🔐 Daily Security & Standards Brief (Jul 19) CVE-2026-58644 — Microsoft SharePoint: patch Microsoft SharePoint and validate deserialization bounds. Full digest 👇 — PCMedicalist Full digest 👇 via PCMedicalist #CyberSecurity #InfoSec https://t.co/3FmOzpYB6N

    @PCMedicalist

    19 Jul 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🔒 #CyberSecurity CVE-2026-58644: Microsoft SharePoint Server Unauthenticated RCE — Detection and… "A critical security vulnerability, CVE-2026-58644, has been identified in Microsoft SharePoint…" 🔗 https://t.co/k084WOpFSE #CyberSecurity #ThreatIntel #critical #zer

    @SecurityAr58409

    19 Jul 2026

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Today's #CTI brief for 2026-07-18: The dangerous systems are still being filed under "internal collaboration" and "security tooling," right up to the point they become a foothold. SharePoint CVE-2026-58644 and FortiSandbox CVE-2026-25089/CVE-2026-39808 have a July 19 federal

    @alphahunt_io

    18 Jul 2026

    45 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🚨 Two critical vulnerabilities in on-premises Microsoft Office SharePoint Server allow RCE without authentication: CVE-2026-58644 and CVE-2026-50522. ▪️ Affected versions: on-premises editions of Microsoft SharePoint Server: SharePoint Server 2016, SharePoint Server 2019,

    @censysio

    17 Jul 2026

    2708 Impressions

    8 Retweets

    32 Likes

    16 Bookmarks

    1 Reply

    1 Quote

  11. 🔴 ALERTĂ: Vulnerabilități critice în Microsoft SharePoint. CVE-2026-50522 și CVE-2026-58644 (CVSS 9.8) permit execuție de cod la distanță. CVE-2026-58644 este exploatată activ. Detalii: https://t.co/9aM8F68MVH #DNSC #CyberSecurity #SharePoint https://t.co/QguYaw5A9d

    @DNSC_RO

    17 Jul 2026

    222 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. CISA adds actively exploited vulnerabilities to KEV: • CVE-2026-39808 & CVE-2026-25089 – Fortinet FortiSandbox (Critical) • CVE-2026-58644 – Microsoft SharePoint (CVSS 9.8) Federal agencies must patch by July 19. Prioritize these updates. #CISA #Vulnerability #Patc

    @ThreatByte

    17 Jul 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Four on-premises SharePoint Server CVEs are actively exploited: CVE-2026-32201 (CVSS 6.5), CVE-2026-45659 (CVSS 8.8), CVE-2026-56164 (CVSS 9.8), and CVE-2026-58644 (CVSS 9.8). #DFIR_Radar https://t.co/ln2QdK28Q8

    @DFIR_Radar

    17 Jul 2026

    190 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    2 Replies

    0 Quotes

  14. CISA KEV catalog adds three actively exploited flaws: FortiSandbox CVE-2026-25089, CVE-2026-39808, and SharePoint CVE-2026-58644. Patch by July 19. #CISA #KEV #Fortinet #FortiSandbox #SharePoint #CVE202658644 #ActivelyExploited #CyberSecurity https://t.co/piHbyDae7Q

    @Daily_CyberSec

    17 Jul 2026

    350 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  15. 🔐 Daily Security & Standards Brief (Jul 17) • CVE-2026-58644 — Microsoft SharePoint Deserialization of Untrusted Data Vulnerability — CISA KEV Vulns → track CVE-2026-58644 and patch Microsoft SharePoint Deserialization of Untru… Full digest 👇 via PCMedicalis

    @PCMedicalist

    17 Jul 2026

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 【常連】米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログにFortiSandboxのCVE-2026-25089及びCVE-2026-39808、並びにSharePointのCVE-2026-58644を追加。対処期限はいずれも3日語の7/19。

    @__kokumoto

    16 Jul 2026

    756 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  17. 🚨 CRITICAL: CVE-2026-58644 - Microsoft SharePoint deserialization flaw (CISA KEV). Unauthorized remote code execution possible. Patch by July 19, 2026. #CVE #PatchNow #ThreatIntel https://t.co/s9HnQljfYf

    @DFIR_Lab

    16 Jul 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 🛡️We added Fortinet FortiSandbox vulnerabilities CVE-2026-25089 & CVE-2026-39808 and Microsoft SharePoint vulnerability CVE-2026-58644 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec

    @CISACyber

    16 Jul 2026

    6150 Impressions

    7 Retweets

    29 Likes

    3 Bookmarks

    2 Replies

    1 Quote

  19. CVE-2026-58644: SharePoint Server deserialization RCE (CVSS 9.8). Unauthenticated, network-exploitable. Sibling CVE demoed at Pwn2Own Berlin. Same July 14 patches as KEV-listed CVE-2026-56164. Investigation workflow → https://t.co/XV8bU4m3Ph

    @hellorecon

    15 Jul 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Running SharePoint? There are at least 4 vulns you want to pay attention to: CVE-2026-55040, CVE-2026-52522, CVE-2026-58644, CVE-2026-56164 unauthenticated RCE, exploits available etc. https://t.co/9moTd0gNju

    @theluemmel

    15 Jul 2026

    2063 Impressions

    2 Retweets

    16 Likes

    8 Bookmarks

    2 Replies

    0 Quotes

  21. 🔒 #CyberSecurity CVE-2026-58644: Microsoft SharePoint Deserialization RCE — Detection and Harden… "CVE-2026-58644 represents a significant escalation in risk for enterprises relying on…" 🔗 https://t.co/vl0JucLagR #CyberSecurity #ThreatIntel #cve202658644 #critical

    @SecurityAr58409

    15 Jul 2026

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations