CVE-2026-58644: Microsoft SharePoint Deserialization of Untrusted Data
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability. Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
- CISA KEV-listed (remediation due 2026-07-19)
- EPSS 15.9% (96.6% percentile)
- CVSS 9.8 critical
Related briefings
- Four SharePoint flaws joined CISA's exploited list in July 2026-08-03
- Hackers exploit a critical Check Point flaw to hijack management servers 2026-07-25
- Hackers exploit critical Fastjson flaw to run code on servers 2026-07-22
- CISA flags four flaws under active attack, including two in WordPress 2026-07-22
- Hackers now exploit a critical WordPress flaw to hijack sites 2026-07-20