Microsoft disclosed and patched CVE-2026-58644, a critical remote code execution flaw in Microsoft SharePoint caused by insecure deserialization of untrusted data (CWE-502). The vulnerability carries a CVSS 9.8 rating and allows an unauthorized attacker to execute arbitrary code over the network by sending a crafted HTTP request, with no user interaction required.
Affected products include SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition prior to patched versions published through Microsoft's security guidance. Reporting on the release said no active exploitation had been confirmed at disclosure, but warned that exploitation is likely because SharePoint is widely deployed in enterprises; organizations were urged to prioritize patching internet-exposed SharePoint systems, review access permissions, and monitor server logs for suspicious activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
After Microsoft confirmed CVE-2026-58644 was being exploited in the wild, CISA added the SharePoint flaw to its Known Exploited Vulnerabilities catalog and ordered federal agencies to remediate it within three days under BOD 26-04.
Microsoft published CVE-2026-58644 on 2026-07-14, disclosing a critical SharePoint remote code execution flaw caused by deserialization of untrusted data. The vulnerability affects multiple SharePoint versions and Microsoft provided a vendor advisory and patches through MSRC.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
vulert.com
Open sourcecybersecuritynews.com
Open sourcesecurityweek.com
Open sourcethehackernews.com
Open sourcerapid7.com
Open sourcethreataft.com
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.