PT-2026-58284 · Microsoft · Sharepoint Server
CVE-2026-58644
·
Published
2026-07-14
·
Updated
2026-08-18
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft SharePoint Enterprise Server 2016 versions prior to 16.0.5556.1005
Microsoft SharePoint Server 2019 versions prior to 16.0.10417.20153
Microsoft SharePoint Server Subscription Edition versions prior to 16.0.19725.20384
Description
An issue exists in the deserialization mechanism of Microsoft SharePoint Server, where the system fails to properly handle untrusted data. This allows an unauthenticated attacker to inject malicious serialized payloads into the server stream via network-facing endpoints, leading to remote code execution (RCE) under the service account context. Successful exploitation can result in full system compromise, unauthorized access to confidential corporate documents, database dumping, and lateral movement across the internal Active Directory domain. This issue has been confirmed as actively exploited in the wild and is included in CISA's Known Exploited Vulnerabilities (KEV) catalog.
Recommendations
For Microsoft SharePoint Enterprise Server 2016, apply the security update version 16.0.5556.1005 or later.
For Microsoft SharePoint Server 2019, apply the security update version 16.0.10417.20153 or later.
For Microsoft SharePoint Server Subscription Edition, apply the security update version 16.0.19725.20384 or later.
Restrict external access to SharePoint interfaces where operationally feasible.
Enable the Antimalware Scan Interface (AMSI) on IIS pools with Full Request Body Scan active to inspect incoming POST requests for deserialization anomalies.
Review IIS, SharePoint ULS, Windows Event Logs, and EDR telemetry for suspicious activity, such as newly created web shells in
c:inetpubwwwroot or unusual PowerShell execution.Fix
DoS
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sharepoint Server