LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-58644: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 16, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 19, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-58644 to its Known Exploited Vulnerabilities catalog on Jul 16, 2026, with a federal patch deadline of Jul 19, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.

Microsoft SharePoint contains a deserialization of untrusted data vulnerability tracked as CVE-2026-58644. An unauthorized attacker can exploit it to execute code over a network. This matters because successful exploitation can lead to remote code execution on SharePoint servers, potentially compromising systems that host collaboration and document management services.

How it works

The weakness is classified as CWE-502. An attacker supplies serialized data that the application deserializes without adequate validation or type checking, allowing the attacker to influence object reconstruction and achieve code execution.

Exploitation occurs over the network when the affected SharePoint component processes untrusted input containing the malicious serialized payload. No further details on payload construction or entry points are provided in the available summary.

Am I affected? How to find it in your systems

Microsoft SharePoint is commonly deployed on-premises as part of collaboration infrastructure. Inventory all SharePoint servers and farms through configuration management databases, asset inventories, or direct queries to installed instances.

How to remediate

Apply the vendor update referenced in the official advisory as the primary remediation step. Follow the exact instructions and sequencing provided by Microsoft.

If you can't patch immediately

Limit network exposure of SharePoint servers through segmentation so that only trusted internal systems can reach management and application endpoints.

If your data may have been exposed

Actively exploited vulnerabilities of this type have led to breaches in other environments. You can run a free exposure scan of your email addresses to check against known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · SharePoint
WeaknessCWE-502
Added to CISA KEVJul 16, 2026
Federal patch deadlineJul 19, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities