Authenticated Site Owners exploit SharePoint deserialization flaw to execute remote code
Attackers are actively exploiting a critical remote code execution flaw in Microsoft SharePoint. This vulnerability allows authenticated Site Owners to inject and execute arbitrary code on the server via untrusted data deserialization. Patch your SharePoint environments immediately to mitigate this risk. 馃毃
Summary
Threat actors have begun targeting a fresh critical-severity remote code execution (RCE) vulnerability in Microsoft SharePoint. The flaw, tracked as CVE-2026-58644, involves the deserialization of untrusted data. While initially not flagged as exploited, Microsoft updated its advisory after detecting active exploitation in the wild.
CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. This move comes alongside warnings regarding other SharePoint defects, including a zero-day flaw (CVE-2026-56164) and a critical security bypass weakness (CVE-2026-55040) that could allow attackers to modify data or disclose files.
Technical details
The CVE-2026-58644 vulnerability is a deserialization issue. In a network-based attack, an attacker with at least Site Owner privileges can write arbitrary code to inject and execute commands remotely on the SharePoint Server.
Microsoft addressed this flaw as part of its July 2026 Patch Tuesday updates. The severity of these defects has prompted rapid response from federal agencies, who are under mandate to patch within three days per CISA's BOD 26-04 guidance.
Exploitation status
Exploitation for CVE-2026-58644 is currently detected in the wild. Microsoft updated its security advisory to reflect this change after initial reports did not include exploitation status.
Additionally, two OS command injection flaws in Fortinet FortiSandbox have been identified as exploited in the wild:
- CVE-2026-25089
- CVE-2026-39808
The latter flaw allows unauthenticated attackers to execute unauthorized code or commands via crafted HTTP requests. Intelligence from Defused flagged these Fortinet vulnerabilities in mid-June.
Defender guidance
Prioritize the following actions to secure your infrastructure:
Microsoft SharePoint Environments
- Apply the July 2026 security updates immediately to resolve CVE-2026-58644, CVE-2026-56164, and CVE-2026-55040.
- Audit Site Owner permissions to ensure that only trusted individuals hold these privileges, as the RCE requires this level of authentication.
Fortinet FortiSandbox Environments
- Apply patches for CVE-2026-25089 and CVE-2026-39808.
- Evaluate internet exposure for all FortiSandbox appliances.
- Follow CISA's "Forensics Triage Requirements" if you suspect an appliance has been compromised.
