Knox CVE Database
/
CVE-2026-58644
Critical
9.8

CVE-2026-58644: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.

Added to the CISA KEV catalog:
July 16, 2026

Overview

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Vulnerability details

Affected vendor
Microsoft
Affected product
SharePoint
Weakness type (CWE)
CWE-502

Microsoft SharePoint fails to validate serialized data before processing it, a CWE-502 weakness where the deserialization routine itself becomes an execution path. When SharePoint deserializes attacker-supplied objects, the runtime reconstructs those objects and invokes their methods, including any attacker-defined logic embedded in the payload. Because the flaw exists in the deserialization layer rather than in authentication or session handling, no credentials are required to reach it. All three on-premises SharePoint product lines are affected: Enterprise Server 2016, Server 2019, and Subscription Edition below their respective patched builds.


An attacker sends a crafted serialized payload over the network to a vulnerable SharePoint endpoint. No authentication and no user interaction are required. When the server deserializes the payload, it executes attacker-controlled code, yielding full remote code execution on the SharePoint host. The impact covers confidentiality, integrity, and availability at the highest severity. The only precondition is network reachability to the SharePoint server. CISA added this vulnerability to the Known Exploited Vulnerabilities catalog, reflecting confirmed exploitation activity.

Severity and impact

9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review IIS and SharePoint Unified Logging Service (ULS) logs for HTTP requests to SharePoint endpoints that return 500-series errors or abnormal response sizes from unauthenticated sessions, which may indicate deserialization payload probing or execution.
  • Monitor the SharePoint application pool worker process (w3wp.exe) for unexpected child process creation, such as cmd.exe or powershell.exe, which would indicate successful deserialization-triggered code execution rather than normal SharePoint operation.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
July 19, 2026

Additional hardening

  • Restrict network access to SharePoint servers at the perimeter and host firewall, permitting only known client IP ranges to reach SharePoint HTTP/HTTPS ports.
  • Disable or isolate internet-facing SharePoint endpoints where external access is not operationally required, reducing the attacker-reachable surface.
  • Run SharePoint application pools under least-privilege service accounts to limit the operating system impact of any successful code execution.
  • Apply CISA BOD 26-04 forensic triage requirements to any SharePoint server that was network-reachable before patching, treating it as potentially compromised.

Key dates

Published (NVD)
July 14, 2026
Added to CISA KEV
July 16, 2026
Remediation deadline
July 19, 2026
Last updated
July 17, 2026

References

Frequently asked questions

Does CVE-2026-58644 affect my FedRAMP authorization?

If Microsoft SharePoint runs inside your authorization boundary, yes — CVE-2026-58644 affects your FedRAMP authorization. CISA has listed this vulnerability in its Known Exploited Vulnerabilities catalog and set a remediation deadline of July 19, 2026. An unpatched Known Exploited Vulnerability inside your boundary is a finding: your assessor and sponsoring agency will expect it either remediated or formally documented with a mitigation before that date arrives.

How does Knox help me handle CVE-2026-58644?

Remediating Microsoft SharePoint is your responsibility under the FedRAMP shared-responsibility model — Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus Knox's automated continuous monitoring platform and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours; maintaining a compliant posture while you do it is not something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on a continuous basis. When something like CVE-2026-58644 surfaces, exposure is identified through ongoing monitoring rather than waiting for an assessor to flag it at a scheduled review.

How do I get FedRAMP authorized with Knox?

Knox operates a FedRAMP-as-a-Service platform. The platform is pre-authorized at FedRAMP High. It spans AWS, Azure, and Google Cloud within a single boundary. Your application inherits 60–80% of the required security controls on day one. No agency sponsor is required to begin. Knox's automated continuous monitoring platform handles control mapping, vulnerability detection, and remediation after you go live. The result is FedRAMP in 90 days for 90% less, without the delays or dependencies that define the traditional route. Book a meeting and Knox maps your path to authorization.

What happens if CVE-2026-58644 isn't remediated by July 19, 2026?

If you miss the July 19, 2026 deadline, CVE-2026-58644 becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list turns a routine continuous-monitoring review into a hard conversation with your sponsoring agency. Meeting the deadline keeps your authorization intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting