• CISA KEV
  • EXPLOITED
  • PATCH AVAILABLE

CVE-2026-58644: pre-auth remote code execution in Microsoft SharePoint

An unauthenticated attacker can trigger unsafe deserialization in Microsoft SharePoint to execute code over a network (CVE-2026-58644). Affects SharePoint Enterprise Server 2016 versions 16.0.0 through before 16.0.5556.1005, SharePoint Server 2019 versions 16.0.0 through before 16.0.10417.20153, and SharePoint Server Subscription Edition 16.0.0 through before 16.0.19725.20384. No user interaction or valid account is required; network access to the vulnerable SharePoint service is sufficient.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.15873
CWE
CWE-502
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent — CISA added this vulnerability to its Known Exploited Vulnerabilities catalog with a rapid fix deadline, and the flaw allows unauthenticated remote code execution over the network; apply vendor updates immediately or isolate affected systems.

What is CVE-2026-58644?

An unauthenticated attacker can trigger unsafe deserialization in Microsoft SharePoint to execute code over a network (CVE-2026-58644). Affects SharePoint Enterprise Server 2016 versions 16.0.0 through before 16.0.5556.1005, SharePoint Server 2019 versions 16.0.0 through before 16.0.10417.20153, and SharePoint Server Subscription Edition 16.0.0 through before 16.0.19725.20384. No user interaction or valid account is required; network access to the vulnerable SharePoint service is sufficient. The weakness is classified as CWE-502 (Deserialization of Untrusted Data).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft SharePoint are affected?

BRANCHAFFECTEDFIXED
Microsoft SharePoint Enterprise Server 2016 16.x16.0.0 – before 16.0.5556.100516.0.5556.1005
Microsoft SharePoint Server 2019 16.x16.0.0 – before 16.0.10417.2015316.0.10417.20153
Microsoft SharePoint Server Subscription Edition 16.x16.0.0 – before 16.0.19725.2038416.0.19725.20384

Is CVE-2026-58644 being exploited?

CISA added CVE-2026-58644 to the Known Exploited Vulnerabilities catalog on 2026-07-16, and U.S. federal agencies were required to apply mitigations or fixes by 2026-07-19.

How to fix CVE-2026-58644

  1. Install Microsoft’s security updates that fix SharePoint: 16.0.5556.1005 (Enterprise 2016), 16.0.10417.20153 (Server 2019), or 16.0.19725.20384 (Subscription Edition).
  2. If you cannot patch immediately, restrict network exposure of SharePoint servers and block untrusted inbound access.
  3. Monitor SharePoint logs and network traffic for anomalous requests and signs of remote code execution attempts.
  4. Follow Microsoft’s mitigation guidance and CISA’s required actions for prioritizing and documenting fixes.

Frequently asked questions

Is CVE-2026-58644 being actively exploited?

CISA added CVE-2026-58644 to its Known Exploited Vulnerabilities catalog on 2026-07-16, requiring agencies to remediate by 2026-07-19.

Which SharePoint versions are affected by CVE-2026-58644?

Microsoft SharePoint Enterprise Server 2016 (16.0.0 through before 16.0.5556.1005), SharePoint Server 2019 (16.0.0 through before 16.0.10417.20153), and SharePoint Server Subscription Edition (16.0.0 through before 16.0.19725.20384) are affected.

Is there a patch for CVE-2026-58644?

Yes; Microsoft published fixes: 16.0.5556.1005 for Enterprise 2016, 16.0.10417.20153 for Server 2019, and 16.0.19725.20384 for Subscription Edition.

Does CVE-2026-58644 require authentication?

No; the vulnerability allows unauthenticated (pre-auth) remote code execution against SharePoint over the network.

References