Microsoft SharePoint contains a critical (CVSS 9.8) deserialization of untrusted data vulnerability that lets an unauthenticated attacker execute code over a network, and CISA has confirmed it is being actively exploited.
What Is It
CVE-2026-58644 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft Office SharePoint. According to the NVD record, it "allows an unauthorized attacker to execute code over a network." It carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network-reachable, low attack complexity, requiring no privileges and no user interaction, with high impact to confidentiality, integrity, and availability.
Why It Matters
CISA added CVE-2026-58644 to its Known Exploited Vulnerabilities catalog on 2026-07-16, confirming active exploitation in the wild. CISA's SSVC assessment rates exploitation as "active," automatable as "yes," and technical impact as "total." The combination of unauthenticated remote code execution, low complexity, and confirmed exploitation makes this an urgent priority for any organization running affected SharePoint on-premises servers. Known ransomware campaign use is currently listed as "Unknown."
What's Vulnerable
Per the NVD data, the following on-premises products (x64-based systems) are affected:
- Microsoft SharePoint Enterprise Server 2016: versions below 16.0.5556.1005
- Microsoft SharePoint Server 2019: versions below 16.0.10417.20153
- Microsoft SharePoint Server Subscription Edition: versions below 16.0.19725.20384
Patch Status
A vendor advisory and patch are available from Microsoft (MSRC). CISA's required action directs organizations to apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 guidance and "Forensics Triage Requirements." For cloud services, follow applicable BOD 26-04 guidance, or discontinue use of the product if mitigations are unavailable. The CISA remediation due date is 2026-07-19.