← Back to Feed
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
CVE-2026-58644
July 31, 2026 · CISA · Severity: CRITICAL
Microsoft SharePoint: Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
Vendor: Microsoft
Product: SharePoint
CISA Date Added: 2026-07-16
CVE: CVE-2026-58644
This vulnerability is actively exploited in the wild according to CISA Known Exploited Vulnerabilities catalog.
Key Takeaways
- CVE-2026-58644 is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog.
- The vulnerability involves privilege escalation or authentication bypass, granting unauthorized access to sensitive functions.
- CISA BOD 26-04 requires remediation within the specified due date — apply vendor mitigations promptly.
- Microsoft SharePoint: Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.