Junglewise Threat Intelligence

CVE-2026-58644: Microsoft SharePoint remote code execution via untrusted deserialization

CVE-2026-58644 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-07-14

Executive brief

Microsoft SharePoint is a widely used collaboration and document management platform. A critical security flaw allows an unauthenticated attacker to remotely execute malicious code on the server over the network. This could lead to a total compromise of the server, including the theft of sensitive corporate data, service disruption, and a foothold for further attacks within the internal network.

Technical details

A deserialization vulnerability (CWE-502) exists in Microsoft SharePoint due to the insecure handling of untrusted data. An unauthenticated attacker can exploit this by sending a specially crafted network request to an affected SharePoint server. Successful exploitation allows for remote code execution (RCE) in the context of the SharePoint service account. The vulnerability affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. Microsoft has released security updates to address this issue; administrators should apply the latest patches for their respective versions.

Affected products

  • Microsoft SharePoint Enterprise Server 2016 16.0.0 to < 16.0.5556.1005
  • Microsoft SharePoint Server 2019 16.0.0 to < 16.0.10417.20153
  • Microsoft SharePoint Server Subscription Edition 16.0.0 to < 16.0.19725.20384

Timeline

  • 2026-07-14: disclosed: Initial disclosure by Microsoft Corporation
  • 2026-07-14: advisory: NVD record published
  • 2026-07-16: exploited: Reported as exploited in the wild per advisory metadata

Related threats