CVE-2026-58644
Analyzed Analyzed - Analysis Complete

Deserialization Flaw in Microsoft Office SharePoint Permits Remote Code Execution

Vulnerability report for CVE-2026-58644, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-17

Assigner: Microsoft Corporation

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-17
Generated
2026-08-03
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
microsoft sharepoint_server 2019
microsoft sharepoint_server 2016
microsoft sharepoint_server to 16.0.19725.20434 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-58644 is a vulnerability in Microsoft Office SharePoint that involves the deserialization of untrusted data. Deserialization is a process where data received over a network or from another source is converted back into an object or data structure that a program can use. In this case, the vulnerability allows an unauthorized attacker to send specially crafted data to a SharePoint server, which, when deserialized, can execute arbitrary code on the server.

This is classified as a remote code execution (RCE) vulnerability, meaning the attacker does not need physical or local access to the system to exploit it. The attack can be carried out over a network, making it particularly dangerous.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying CVE-2026-58644 on a network or system. Detection typically involves checking for vulnerable versions of Microsoft Office SharePoint or monitoring for unusual deserialization activity, but no details are available in the given resources.

For accurate detection guidance, refer to Microsoft's official documentation or security advisories, which may provide updated tools or scripts for vulnerability assessment.

Impact Analysis

If you or your organization use Microsoft Office SharePoint, this vulnerability could have severe consequences. Here are some potential impacts:

  • Unauthorized code execution: An attacker could execute malicious code on your SharePoint server, potentially gaining control over it.
  • Data breaches: The attacker could access, modify, or delete sensitive data stored on or accessible through the SharePoint server.
  • Network compromise: The attacker could use the compromised SharePoint server as a foothold to launch further attacks within your network.
  • Service disruption: The attacker could disrupt SharePoint services, causing downtime and affecting business operations.

Given the CVSS base score of 9.8 (Critical), this vulnerability is highly severe and poses a significant risk if left unpatched.

Compliance Impact

This vulnerability can have serious implications for compliance with various standards and regulations, depending on the type of data your organization handles. Here are some potential impacts:

  • GDPR (General Data Protection Regulation): If the SharePoint server stores or processes personal data of EU citizens, a breach resulting from this vulnerability could lead to unauthorized access or disclosure of that data. This would likely be considered a reportable breach under GDPR, potentially resulting in significant fines (up to 4% of global annual revenue or €20 million, whichever is higher).
  • HIPAA (Health Insurance Portability and Accountability Act): For organizations handling protected health information (PHI) in the U.S., exploitation of this vulnerability could lead to unauthorized access to PHI. This would constitute a breach under HIPAA, requiring notification to affected individuals, the Department of Health and Human Services, and potentially the media. It could also result in fines and corrective action plans.
  • Other regulations: Depending on your industry, other regulations like PCI DSS (for payment card data), SOX (for financial data), or industry-specific standards may also be impacted. Failure to protect systems from known vulnerabilities could be seen as a violation of these standards.

To maintain compliance, it is critical to apply patches or mitigations for this vulnerability as soon as possible and ensure that your organization’s security controls are robust enough to detect and prevent such attacks.

Mitigation Strategies

To mitigate CVE-2026-58644, apply the security updates provided by Microsoft as soon as possible. The vulnerability is classified as critical with a CVSS base score of 9.8, indicating severe risk.

  • Check the Microsoft Security Response Center (MSRC) update guide for the latest patches and installation instructions.
  • Ensure all instances of Microsoft Office SharePoint are updated to the latest secure version.
  • If immediate patching is not feasible, consider implementing network-level protections such as firewalls or intrusion detection systems to monitor and block suspicious deserialization attempts.
  • Restrict network access to SharePoint servers to trusted sources only until the patch is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-58644. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart