Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-58644

Published 2026-07-14
Updated 2 months ago
Vendor/s
Microsoft
Product/s
SharePoint
Version/s
* > 16.0.19725.20434
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
9.8
/ 10
Critical
Severity Details
Base score
9.8 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

CVE-2026-58644 is a critical 9.8 CVSS RCE vulnerability in Microsoft SharePoint. Actively exploited; immediate patching of affected servers is required.

CPE

Microsoft logo
Microsoft
Product Version Start Version End (excl.) Status
sharepoint_server * 16.0.19725.20434 vulnerable
sharepoint_server 2016 2016 vulnerable
sharepoint_server 2019 2019 vulnerable

Related weakness (CWE)

CWE-502

Remediation plan

1

Apply official patches

Immediately download and install the security updates provided by Microsoft specifically for SharePoint Server 2016, 2019, and Subscription Edition to address the underlying deserialization flaw.

2

Update affected systems

Ensure all SharePoint Server instances are updated to version 16.0.19725.20434 or higher. Verify that all members of the server farm are running consistent, patched build numbers.

3

Restrict access

Minimize the attack surface by placing SharePoint servers behind a Web Application Firewall (WAF) and restricting access to trusted IP ranges or requiring a VPN for remote access.

4

Monitor for exploitation

Audit system logs for unusual service account activity and monitor for suspicious child processes spawning from 'w3wp.exe' or 'OWSTIMER.EXE', which are common indicators of remote code execution.

Detection Guidance

"Focus detection on identifying abnormal deserialization patterns in web traffic and monitoring SharePoint logs for unexpected errors related to data processing. Look for suspicious process execution, such as 'cmd.exe' or 'powershell.exe' being launched by SharePoint worker processes. Additionally, monitor for unusual outbound network connections originating from the SharePoint server and utilize EDR signatures designed to catch common .NET deserialization gadget chains used in RCE attacks."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management