PT-2026-58284 · Microsoft · Sharepoint Server
CVE-2026-58644
·
Published
2026-07-14
·
Updated
2026-07-21
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft SharePoint Enterprise Server 2016 versions prior to 16.0.5556.1005
Microsoft SharePoint Server 2019 versions prior to 16.0.10417.20153
Microsoft SharePoint Server Subscription Edition versions prior to 16.0.19725.20384
Description
This issue involves the deserialization of untrusted data within core SharePoint web functions. Deserialization is the process of converting a data stream back into an object, and when this process is handled insecurely, it can allow an attacker to inject malicious payloads. An unauthenticated remote attacker can exploit this flaw to execute arbitrary code on the server under the service account context, potentially leading to full system compromise, access to confidential corporate documents, and lateral movement across the internal Active Directory domain. The vulnerability is network-exploitable and has been confirmed as actively exploited in the wild, including a breach of the Homeland Security Information Network.
Recommendations
Apply the security updates for Microsoft SharePoint Enterprise Server 2016 versions prior to 16.0.5556.1005.
Apply the security updates for Microsoft SharePoint Server 2019 versions prior to 16.0.10417.20153.
Apply the security updates for Microsoft SharePoint Server Subscription Edition versions prior to 16.0.19725.20384.
Restrict external access to SharePoint interfaces where operationally feasible.
Enable the Antimalware Scan Interface (AMSI) on IIS pools with Full Request Body Scan active to inspect incoming POST requests for deserialization anomalies.
Fix
DoS
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sharepoint Server