PT-2026-58284 · Microsoft · Sharepoint Server

CVE-2026-58644

·

Published

2026-07-14

·

Updated

2026-08-18

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft SharePoint Enterprise Server 2016 versions prior to 16.0.5556.1005 Microsoft SharePoint Server 2019 versions prior to 16.0.10417.20153 Microsoft SharePoint Server Subscription Edition versions prior to 16.0.19725.20384
Description An issue exists in the deserialization mechanism of Microsoft SharePoint Server, where the system fails to properly handle untrusted data. This allows an unauthenticated attacker to inject malicious serialized payloads into the server stream via network-facing endpoints, leading to remote code execution (RCE) under the service account context. Successful exploitation can result in full system compromise, unauthorized access to confidential corporate documents, database dumping, and lateral movement across the internal Active Directory domain. This issue has been confirmed as actively exploited in the wild and is included in CISA's Known Exploited Vulnerabilities (KEV) catalog.
Recommendations For Microsoft SharePoint Enterprise Server 2016, apply the security update version 16.0.5556.1005 or later. For Microsoft SharePoint Server 2019, apply the security update version 16.0.10417.20153 or later. For Microsoft SharePoint Server Subscription Edition, apply the security update version 16.0.19725.20384 or later. Restrict external access to SharePoint interfaces where operationally feasible. Enable the Antimalware Scan Interface (AMSI) on IIS pools with Full Request Body Scan active to inspect incoming POST requests for deserialization anomalies. Review IIS, SharePoint ULS, Windows Event Logs, and EDR telemetry for suspicious activity, such as newly created web shells in c:inetpubwwwroot or unusual PowerShell execution.

Fix

DoS

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09928
CVE-2026-58644

Affected Products

Sharepoint Server