CVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
A critical remote code execution vulnerability (CVE-2026-58644) in Microsoft SharePoint Server is being actively exploited in the wild. The flaw affects on-premises versions including SharePoint Enterprise Server 2016, SharePoint Server 2019, and Subscription Edition. Attackers can exploit it without authentication due to unsafe deserialization of untrusted data. Microsoft has issued urgent security updates, and CISA added the issue to its KEV list. Organizations are advised to apply the July 14, 2026 patches immediately and monitor for signs of exploitation using tools like Microsoft Defender and AMSI.
Overview
On July 14, 2026, Microsoft CVE-2026-58644">published a security advisory addressing CVE-2026-58644">CVE-2026-58644, a critical remote code execution (RCE) vulnerability affecting on-premises Microsoft SharePoint Server deployments. The vulnerability, which carries a CVSS v3.1 score of 9.8 (Critical), results from the deserialization of untrusted data (CWE-502) and allows an unauthenticated attacker to execute arbitrary code.…