Microsoft SharePoint code execution vulnerability CVE-2026-58644 is now under active exploitation, prompting urgent warnings from CISA. This flaw enables attackers to execute arbitrary code on vulnerable servers, and enterprises using SharePoint should take immediate action to mitigate the risk.
Details of the Microsoft SharePoint Code Execution Vulnerability
CVE-2026-58644 is a critical vulnerability found in Microsoft SharePoint, widely used for document management and collaboration in business environments. This flaw was officially added to CISA’s Known Exploited Vulnerabilities (KEV) catalogue on 16 July 2026, confirming that attackers are exploiting it in real-world attacks.
The root cause of the vulnerability is unsafe deserialization of untrusted data within SharePoint. Specifically, the flaw is classified as CWE-502 (Deserialization of Untrusted Data), where an application processes serialized objects received from external or untrusted sources without proper validation or sanitisation. In this scenario, threat actors can craft malicious objects and send them to the target SharePoint server. If the server does not adequately check this data, the attacker’s code can be executed within the server environment.
The risk is especially high for SharePoint servers exposed to the internet. These servers are particularly attractive to attackers due to their widespread use and often central role in business operations.
How Attackers Exploit CVE-2026-58644 in SharePoint
The CVE-2026-58644 vulnerability allows unauthenticated remote code execution. This means attackers do not require valid credentials to exploit the flaw. By sending specially crafted serialized objects to the vulnerable SharePoint server, they can execute arbitrary commands and deploy additional malicious tools.
Once the flaw is exploited, attackers gain a foothold in the target environment. Typical post-exploitation activities observed with similar vulnerabilities include:
- Deploying web shells for persistent remote access
- Moving laterally across the network to compromise further systems
- Stealing sensitive data stored in SharePoint or connected resources
- Escalating privileges to gain deeper access within the organisation
While there are no confirmed links to specific ransomware campaigns as of the latest reports, deserialization vulnerabilities have historically been leveraged by both ransomware operators and advanced persistent threat (APT) groups due to their reliability and high impact. The unauthenticated nature of this bug significantly increases its risk profile, as attackers can exploit it remotely without needing an initial foothold.
Timeline and Exploitation Status
- Early July 2026: Microsoft issues patches and guidance for CVE-2026-58644 as part of its regular Patch Tuesday update cycle.
- 16 July 2026: CISA adds the vulnerability to its KEV catalogue, indicating that exploitation in the wild has been observed and verified.
- Current status: Exploitation is ongoing, and both government and private sector organisations are urged to act quickly.
In response, CISA has issued a Binding Operational Directive (BOD 26-04) for federal agencies, requiring them to assess whether any SharePoint instances are internet-facing, apply Microsoft’s security updates, and follow recommended mitigation steps within a specified timeframe.
Who Is Affected and Which Versions Are Vulnerable?
The vulnerability affects Microsoft SharePoint servers that process serialized data without adequate validation. Although Microsoft has not published a comprehensive list of all affected product versions, it is understood that multiple supported SharePoint versions are impacted. Organisations running on-premises SharePoint servers, especially those exposed to the internet, are at the greatest risk.
- Enterprises using SharePoint for internal and external collaboration
- Government agencies with public-facing SharePoint portals
- SMEs relying on SharePoint document management without robust network segmentation
Organisations are strongly advised to consult Microsoft’s official guidance and security update documentation to determine if their specific SharePoint version requires immediate action.
Detection, Response, and Official Guidance
CISA provides clear steps for detecting signs of compromise and responding to a potential attack:
- Review SharePoint logs for evidence of unusual processes or access patterns
- Monitor for unauthorised file uploads or suspicious authentication attempts
- Implement endpoint detection and response (EDR) tools to catch abnormal behaviours
- Follow CISA’s Forensics Triage Requirements for compromised SharePoint servers
Microsoft has released security updates and mitigations to address CVE-2026-58644. Organisations unable to immediately apply fixes should consider disabling vulnerable services until protections are in place. Restricting external access to SharePoint servers and prioritising patching of internet-facing instances are also strongly encouraged.
Why This SharePoint Vulnerability Matters
SharePoint is deeply integrated into enterprise workflows, making any compromise potentially devastating. The active exploitation of CVE-2026-58644 means attackers are already targeting unpatched systems. Rapid patching and strict monitoring are essential to prevent breaches, data loss, or further lateral movement within affected networks.
What Organisations Should Do Now
- Apply Microsoft’s security updates addressing CVE-2026-58644 as a top priority
- Audit your SharePoint exposure and restrict access where possible
- Utilise logging, EDR, and threat hunting to spot indicators of compromise
- Follow CISA and Microsoft guidance for detection, mitigation, and response
With the risk of exploitation confirmed and the vulnerability impacting a core business platform, organisations should ensure remediations are in place without delay.
Originally reported by cybersecuritynews.com.






