Exploitation of Critical Vulnerability in Microsoft SharePoint Server
Successful exploitation of CVE-2026-58644 could allow an unauthenticated attacker to execute code remotely
Summary
Successful exploitation of CVE-2026-58644 could allow an unauthenticated attacker to execute code remotely
Affected platforms
The following platforms are known to be affected:
Threat details
Exploitation of CVE-2026-58644
Microsoft has reported exploitation of CVE-2026-58644 and this vulnerability has been added to the US Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) Catalog.
The NHS England National CSOC assesses further exploitation as likely.
Introduction
Microsoft has released security updates to address a critical vulnerability affecting on-premises deployments of Microsoft SharePoint Server. Successful exploitation could allow an unauthenticated attacker to execute code remotely.
- CVE-2026-58644 - Deserialisation of Untrusted Data vulnerability - CVSSv3 score: 9.8
SharePoint Server 2016 and 2019 are no longer supported
As of 14 July 2026, Microsoft's extended support for SharePoint Server 2016 and SharePoint Server 2019 has come to an end, therefore these products are now unsupported by Microsoft. Organisations are strongly encouraged to switch to a supported version.
Remediation advice
Affected organisations must review Microsoft's security advisory for CVE-2026-58644 and follow the remediation steps below.
Remediation steps
| Type | Step |
|---|---|
| Patch |
Required: Patch to a fixed version. Organisations must update on-premises deployments of Microsoft SharePoint Server to a fixed version:
Note: SharePoint Server 2016 and 2019 are no longer supported. Organisations should migrate to a supported version. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644 |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 20 July 2026 11:39 am