CVE-2026-58644
published 2026-07-14CVE-2026-58644: Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
PriorityP190critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-07-19
Exploited in the wild
EPSS
1.47%
70.8th percentile
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < 16.0.5556.1005 | 16.0.5556.1005 |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < 16.0.10417.20153 | 16.0.10417.20153 |
| microsoft | microsoft_sharepoint_server_subscription_edition | >= 16.0.0 < 16.0.19725.20384 | 16.0.19725.20384 |
| microsoft | sharepoint_server | < 16.0.19725.20434 | 16.0.19725.20434 |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for AMSI/Microsoft Defender signature 'Exploit:Script/SuspSignoutReqBody.A' — triggers on suspicious request body content; applies to SharePoint Server Subscription Edition and indicates observed exploitation attempts are blocked by this signature. ↗
- →Monitor for AMSI/Microsoft Defender signature 'Exploit:Script/ToolPaneAuthBypass.A' — triggers on request header scanning; applies to SharePoint Server 2016, 2019, and Subscription Edition. ↗
- →Ensure AMSI integration is enabled on all SharePoint web applications to enable detection of exploitation attempts via the published signatures. ↗
- ·No public network-based IOCs (IPs, domains, URLs) have been disclosed at time of publication; detection relies entirely on AMSI/Defender signatures. ↗
- ·The vulnerability is exploitable by unauthenticated attackers over the network (CVSS 9.8), meaning no credentials are required — perimeter controls alone are insufficient. ↗
- ·Only on-premises SharePoint Server deployments are affected (Enterprise Server 2016, Server 2019, Subscription Edition); SharePoint Online/cloud is not listed as affected. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft SharePoint Server Object Serialization deserialization
vuldb·2026-07-19·CVSS 9.8
CVE-2026-58644 [CRITICAL] Microsoft SharePoint Server Object Serialization deserialization
A vulnerability, which was classified as critical, was found in Microsoft SharePoint Server. This issue affects some unknown processing of the component Object Serialization Handler. The manipulation results in deserialization.
This vulnerability is reported as CVE-2026-58644. The attack can be launched remotely. Moreover, an exploit is present.
GHSA
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
ghsa_unreviewed·2026-07-14
CVE-2026-58644 [CRITICAL] CWE-502 Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
VulnCheck
Microsoft SharePoint Deserialization of Untrusted Data
vulncheck·2026·CVSS 9.8
CVE-2026-58644 [CRITICAL] Microsoft SharePoint Deserialization of Untrusted Data
Microsoft SharePoint Deserialization of Untrusted Data
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Affected: Microsoft SharePoint
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Jul
CISA
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
cisa·2026-07-16·CVSS 9.8
CVE-2026-58644 [CRITICAL] CWE-502 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Vulnerability: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Affected: Microsoft SharePoint
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Notes: https://msrc.microso
No detection rules found.
No public exploits indexed.
Hackernews
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
blogs_hackernews·2026-07-21·CVSS 9.8
CVE-2026-50522 [CRITICAL] Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr .
The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network. Microsoft credited DEVCORE researcher "splitline" with discovering and reporting the flaw.
"In a network-based attack, an attacker authenticated as at least a Site Owner, could w
Hackernews
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
blogs_hackernews·2026-07-20·CVSS 5.9
CVE-2026-63030 [MEDIUM] ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.
The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch.
Here is the full recap of what broke, what was exploited, and what needs attention now.
## ⚡ Threat of the Week
New wp2shell WordPress Core Flaw Lets Unauthe
Hackernews
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
blogs_hackernews·2026-07-17·CVSS 6.5
CVE-2026-58644 [MEDIUM] CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities ( KEV ) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026.
The vulnerability in question is CVE-2026-58644 (CVSS score: 9.8), a critical deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute arbitrary code.
"In a network-based attack, an attacker authenticated as at least a Sit
Rapid7
CVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
blogs_rapid7·2026-07-17·CVSS 9.8
CVE-2026-58644 [CRITICAL] CVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
## Overview
On July 14, 2026, Microsoft published a security advisory addressing CVE-2026-58644 , a critical remote code execution (RCE) vulnerability affecting on-premises Microsoft SharePoint Server deployments. The vulnerability, which carries a CVSS v3.1 score of 9.8 (Critical), results from the deserialization of untrusted data ( CWE-502 ) and allows an unauthenticated attacker to execute arbitrary code.
Microsoft confirmed active exploitation of CVE-2026-58644, and the vulnerability was subsequently added to CISA’s Known Exploited Vulnerabilities ( KEV ) catalog on July 16, 2026. In parallel, CISA published guidance recommending organizations immediately apply Microsoft’s security updates and leverage Microsoft Defender and AMSI detections to identify exploitation attempts.
Affect
Tenable
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
blogs_tenable·2026-07-16·CVSS 6.5
CVE-2026-32201 [MEDIUM] CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
## CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments.
## Key Takeaways
CISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware for persistence.
Two additional SharePoint Server vulnerabilities disclosed on July 14, 2026, CVE-2026-55040 and CVE-2026-58644, were not yet
Rapid7
Patch Tuesday - July 2026
blogs_rapid7·2026-07-14·CVSS 9.6
CVE-2026-58617 [CRITICAL] Patch Tuesday - July 2026
Microsoft is publishing 622 vulnerabilities on July 2026 Patch Tuesday , including a record-breaking 416 Windows vulnerabilities. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today, both of which are listed on CISA KEV, as well as public disclosure for one other. As usual, browser vulns are not included in the Patch Tuesday count above. Rapid7 noted last month that Microsoft no longer enumerates Chromium CVEs in the Security Update Guide. However, Microsoft has now taken the pursuit of minimalism much further, since today’s Security Update Guide no longer lists out even Microsoft vulnerabilities! Instead, we now receive a summary table of vulnerability counts by product family, as well as a new slimline “Notable CVEs” section. All of this only ser
Talos
Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
blogs_talos·2026-07-14·CVSS 8.8
CVE-2026-56155 [HIGH] Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical".
Microsoft notes that two of the vulnerabilities disclosed this month have been exploited in the wild.
CVE-2026-56155 is an important-severity elevation of privilege vulnerability in Active Directory Federation Services (AD FS) caused by insufficient granularity of access control. An authorized attacker could use it to elevate privileges locally.
CVE-2026-56164 is a moderate-severity vulnerability in Microsoft SharePoint Server caused by missing authentication for a critical function. An unauthorized attacker could exploit i
Sans Isc
Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)
blogs_sans_isc·2026-07-14·CVSS 6.1
CVE-2026-56155 [MEDIUM] Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)
Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here
Published: 2026-07-14. Last Updated: 2026-07-14 19:14:58 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
This patch Tuesday includes a staggering 622 vulnerabilities, not including another 427 vulnerabilities in Chromium, affecting Microsoft's Edge browser. 62 of the vulnerabilities are rated critical. One was disclosed before today, and two have already been exploited.
Given the large number of vulnerabilities, it is difficult to point out "noteworthy" issues.
Already exploited vulnerabilities:
CVE-2026-56155 : Active Directory Federation Services Elevation of Privilege Vulnerability. This is an important (not critical) vulnerablity.
CVE-2026-56164: Microsoft SharePoint Server Elevation of Privilege Vulnerability. Micr
Qualys
Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review
blogs_qualys·2026-07-14
CVE-2026-50661 Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review
## Table of Contents
Microsoft Patch Tuesday forJuly2026
Adobe Patch for July 2026
Zero-day Vulnerabilities Patched inJulyPatch Tuesday Edition
Critical Severity Vulnerabilities Patched inJulyPatch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Qualys Monthly Webinar Series
Microsoft’s July 2026 Patch Tuesday delivers security updates for a broad range of products and services, including several vulnerabilities that pose significant risks to enterprise environments. As attackers continue to target unpatched systems, the timely deployment of these updates remains one of the most effective defenses against exploitation. This blog provides an overview of the month’s key security fixes, highlights the most critical vulnerabilities, and offers guidanc
Crowdstrike
July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days
blogs_crowdstrike
CVE-2026-56155 July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days
AIDR: How CrowdStrike Is Defining the Next Era of Cybersecurity Jul 15, 2026
July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days Jul 14, 2026
Why AI Governance Without Guardrails Is Theater Jul 09, 2026
Falcon Secure Access Sets the Standard for Zero Trust Browser Security Jul 08, 2026
AIDR: How CrowdStrike Is Defining the Next Era of Cybersecurity Jul 15, 2026
July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days Jul 14, 2026
Why AI Governance Without Guardrails Is Theater Jul 09, 2026
Falcon Secure Access Sets the Standard for Zero Trust Browser Security Jul 08, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&
2026-07-14
Published
2026-07-16
Added to CISA KEV
Exploited in the wild