All stories
criticalExploited VulnerabilitiesCVE-2026-58644

Attackers exploit unauthenticated remote code execution vulnerabilities in Microsoft SharePoint environments

馃毃 Critical remote code execution is being actively exploited in Microsoft SharePoint environments. Attackers can execute arbitrary code over a network without authentication by targeting deserialization flaws. Patch your SharePoint Enterprise Server 2016 instances immediately.

Summary

CISA has added a critical vulnerability affecting Microsoft SharePoint Enterprise Server 2016 to its Known Exploited Vulnerabilities catalog. The flaw, identified as CVE-2026-58644, allows an unauthorized attacker to execute code over a network. This vulnerability is characterized by a CVSS score of 9.8, reflecting its high impact on confidentiality, integrity, and availability.

The exploitation involves the deserialization of untrusted data within Microsoft Office SharePoint. Because the attack can be launched remotely without requiring user interaction or existing credentials, it presents a significant risk to any organization running affected versions of the software.

Technical details

The core of CVE-2026-58644 lies in how Microsoft SharePoint handles incoming data during deserialization processes. When an application takes untrusted input and converts it back into an object without sufficient validation, an attacker can inject malicious payloads that the server then executes as legitimate instructions.

In this specific instance, the vulnerability exists within the Microsoft Office SharePoint component. An attacker can send a specially crafted request over the network to trigger the deserialization flaw. This results in remote code execution (Rce), granting the attacker the ability to run commands on the underlying server infrastructure.

The impact is high across all three security pillars:

  • Confidentiality: High; attackers can access sensitive data stored within SharePoint.
  • Integrity: High; unauthorized users can modify files or system configurations.
  • Availability: High; the vulnerability can be used to disrupt services or crash the server.

Exploitation status

This vulnerability is currently being exploited in the wild. CISA added CVE-2026-58644 to its KEV catalog on July 16, 2026, indicating that active, successful exploitation has been observed by security researchers or threat intelligence feeds.

The presence of this vulnerability on the KEV list means defenders should treat any unpatched SharePoint Enterprise Server 2016 instance as an immediate target for remote attackers.

Defender guidance

Prioritize patching all instances of Microsoft SharePoint Enterprise Server 2016. Because the attack vector is network-based and requires no authentication, perimeter defenses alone may not be sufficient if the service is exposed to untrusted networks.

Immediate actions:

  • Apply the security updates provided by Microsoft via their official update guide.
  • Audit all SharePoint environments to identify any legacy 2016 installations that may have been overlooked during previous patch cycles.
  • Monitor network traffic for unusual deserialization patterns or unexpected outbound connections originating from your SharePoint servers.

Sources

  1. https://thehackernews.com/2026/07/cisa-adds-exploited-sharepoint-rce-zero.html
  2. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -