CVE-2026-58644
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Jul 16, 2026
- US federal agencies must remediate it by Jul 19, 2026 (BOD 22-01)
- Attacked 1 day before the vulnerability was made public
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Source: CISA KEV · Aug 20, 2026 Aug 7, 2026 Jul 24, 2026 Jul 18, 2026 Jul 17, 2026 Jul 16, 2026
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAffected products
| Vendors | Product | Versions |
|---|---|---|
| microsoft | sharepoint server | < 16.0.19725.20434 |
Related articles
VulnerabilitiesFour Critical Vulnerabilities Exploited Against macOS, SharePoint, VMware vCenter, and Windows
CISA has added four actively exploited critical vulnerabilities to its Known Exploited Vulnerabilities KEV catalog. The flaws affect Apple macOS,
VulnerabilitiesCVE-2026-69836: Critical Vulnerability Exploited in Microsoft Entra ID, but Customers Need Take No Action
Microsoft fixes critical CVE-2026-69836 in Entra ID, fully mitigated. No patches needed. Exploited in attacks but resolved.
VulnerabilitiesBTR Reforged: Microsoft Defender’s Driver Can Be Weaponized Against Windows Security
BTR Reforged: Abusing Defender's driver to bypass Windows security. Requires admin access, affects Windows 7-11. Presented at Black Hat 2026.
VulnerabilitiesAmazon Kiro: a prompt injection exfiltrates data from the workspace with a single message
Researchers reveal a prompt injection flaw in Amazon Kiro that exfiltrates workspace data via a single message. Affects IDE versions, patched in update.
VulnerabilitiesFalconFlank: PoC Released for Privilege Escalation in CrowdStrike Falcon
FalconFlank PoC targets CrowdStrike Falcon Sensor privilege escalation via Office macro remediation on Windows 11 25H2 and Server 2025. No CVE yet.
VulnerabilitiesMicrosoft Fixes 398 Vulnerabilities as Exploited Windows Kernel Flaw Enters CISA KEV
Microsoft patched 398 vulnerabilities, including exploited Windows kernel flaw CVE-2026-68820 now in CISA KEV. Patch immediately.
VulnerabilitiesMicrosoft Patches 966 Flaws as Two Windows Zero-Days Come Under Active Attack
Microsoft fixed 966 flaws in record September Patch Tuesday, including two exploited Windows privilege-escalation zero-days leading to SYSTEM access.
This product uses the NVD API but is not endorsed or certified by the NVD.