PT-2026-58284 · Microsoft · Sharepoint Server

CVE-2026-58644

·

Published

2026-07-14

·

Updated

2026-07-21

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft SharePoint Enterprise Server 2016 versions prior to 16.0.5556.1005 Microsoft SharePoint Server 2019 versions prior to 16.0.10417.20153 Microsoft SharePoint Server Subscription Edition versions prior to 16.0.19725.20384
Description This issue involves the deserialization of untrusted data within core SharePoint web functions. Deserialization is the process of converting a data stream back into an object, and when this process is handled insecurely, it can allow an attacker to inject malicious payloads. An unauthenticated remote attacker can exploit this flaw to execute arbitrary code on the server under the service account context, potentially leading to full system compromise, access to confidential corporate documents, and lateral movement across the internal Active Directory domain. The vulnerability is network-exploitable and has been confirmed as actively exploited in the wild, including a breach of the Homeland Security Information Network.
Recommendations Apply the security updates for Microsoft SharePoint Enterprise Server 2016 versions prior to 16.0.5556.1005. Apply the security updates for Microsoft SharePoint Server 2019 versions prior to 16.0.10417.20153. Apply the security updates for Microsoft SharePoint Server Subscription Edition versions prior to 16.0.19725.20384. Restrict external access to SharePoint interfaces where operationally feasible. Enable the Antimalware Scan Interface (AMSI) on IIS pools with Full Request Body Scan active to inspect incoming POST requests for deserialization anomalies.

Fix

DoS

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09928
CVE-2026-58644

Affected Products

Sharepoint Server