๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-58644: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Summary
Microsoft SharePoint has a deserialization of untrusted data vulnerability (a flaw where the software unsafely processes data from untrusted sources, allowing attackers to inject malicious code), which lets unauthorized attackers execute code over a network. This vulnerability is actively being exploited in real-world attacks. Organizations must apply vendor-provided mitigations by July 19, 2026, following CISA's BOD 26-04 guidance on prioritizing security updates, or stop using the product if no fix is available.
Solution / Mitigation
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 Prioritizing Security Updates Based on Risk guidance. For cloud services, follow applicable BOD 26-04 guidance or discontinue use of the product if mitigations are unavailable. Consult Microsoft's update guide at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644 for specific patches or fixes.
Vulnerability Details
EPSS: 1.3%
Yes
๐ฅ Actively Exploited
July 15, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-58644
First tracked: July 16, 2026 at 02:01 PM
Classified by LLM (prompt v3) ยท confidence: 95%