CVE-2026-58644 is a critical 9.8 CVSS RCE vulnerability in Microsoft SharePoint. Actively exploited; immediate patching of affected servers is required.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| sharepoint_server | * | 16.0.19725.20434 | vulnerable |
| sharepoint_server | 2016 | 2016 | vulnerable |
| sharepoint_server | 2019 | 2019 | vulnerable |
Immediately download and install the security updates provided by Microsoft specifically for SharePoint Server 2016, 2019, and Subscription Edition to address the underlying deserialization flaw.
Ensure all SharePoint Server instances are updated to version 16.0.19725.20434 or higher. Verify that all members of the server farm are running consistent, patched build numbers.
Minimize the attack surface by placing SharePoint servers behind a Web Application Firewall (WAF) and restricting access to trusted IP ranges or requiring a VPN for remote access.
Audit system logs for unusual service account activity and monitor for suspicious child processes spawning from 'w3wp.exe' or 'OWSTIMER.EXE', which are common indicators of remote code execution.
"Focus detection on identifying abnormal deserialization patterns in web traffic and monitoring SharePoint logs for unexpected errors related to data processing. Look for suspicious process execution, such as 'cmd.exe' or 'powershell.exe' being launched by SharePoint worker processes. Additionally, monitor for unusual outbound network connections originating from the SharePoint server and utilize EDR signatures designed to catch common .NET deserialization gadget chains used in RCE attacks."
Experience superior visibility and a simpler approach to cyber risk management