Skip to main content

Exploitation of Critical Vulnerability in Microsoft SharePoint Server

Successful exploitation of CVE-2026-58644 could allow an unauthenticated attacker to execute code remotely

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Successful exploitation of CVE-2026-58644 could allow an unauthenticated attacker to execute code remotely


Threat details

Exploitation of CVE-2026-58644

Microsoft has reported exploitation of CVE-2026-58644 and this vulnerability has been added to the US Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) Catalog.

The NHS England National CSOC assesses further exploitation as likely.


Introduction

Microsoft has released security updates to address a critical vulnerability affecting on-premises deployments of Microsoft SharePoint Server. Successful exploitation could allow an unauthenticated attacker to execute code remotely.

  • CVE-2026-58644 - Deserialisation of Untrusted Data vulnerability - CVSSv3 score: 9.8

SharePoint Server 2016 and 2019 are no longer supported

As of 14 July 2026, Microsoft's extended support for SharePoint Server 2016 and SharePoint Server 2019 has come to an end, therefore these products are now unsupported by Microsoft. Organisations are strongly encouraged to switch to a supported version.


Remediation advice

Affected organisations must review Microsoft's security advisory for CVE-2026-58644 and follow the remediation steps below.


Remediation steps

Type Step
Patch

Required: Patch to a fixed version.

Organisations must update on-premises deployments of Microsoft SharePoint Server to a fixed version:

  • SharePoint Enterprise Server 2016: build 16.0.5556.1005
  • SharePoint Server 2019: build 16.0.10417.20153
  • SharePoint Server Subscription Edition: build 16.0.19725.20384

Note: SharePoint Server 2016 and 2019 are no longer supported. Organisations should migrate to a supported version.


https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644


Last edited: 20 July 2026 11:39 am