## Overview
CISA added CVE-2026-58644 to its Known Exploited Vulnerabilities (KEV) list on July 16, 2026. This vulnerability affects Microsoft SharePoint and allows unauthorized attackers to execute code over a network. The high CVSS score of 9.8 indicates a critical risk.
## Technical Details
The vulnerability arises from a deserialization of untrusted data flaw in Microsoft SharePoint. Attackers can exploit this weakness to send specially crafted requests that lead to remote code execution. The issue is particularly concerning as it can be triggered remotely, making it easier for attackers to target systems without physical access.
## Impact
If exploited, CVE-2026-58644 could allow attackers to gain full control over affected SharePoint servers. This could lead to unauthorized access to sensitive data, disruption of services, and further network compromise. Organizations using SharePoint should be aware that the risk of exploitation is elevated, especially since evidence of active exploitation has surfaced.
## Mitigation
Defenders should prioritize applying the latest security patches released by Microsoft for SharePoint. Regularly updating systems and monitoring for unusual activity can help mitigate risks. Additionally, organizations should implement network segmentation and strict access controls to limit potential attack vectors.
CSURFACE Threat Sensor