Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Microsoft SharePoint fails to validate serialized data before processing it, a CWE-502 weakness where the deserialization routine itself becomes an execution path. When SharePoint deserializes attacker-supplied objects, the runtime reconstructs those objects and invokes their methods, including any attacker-defined logic embedded in the payload. Because the flaw exists in the deserialization layer rather than in authentication or session handling, no credentials are required to reach it. All three on-premises SharePoint product lines are affected: Enterprise Server 2016, Server 2019, and Subscription Edition below their respective patched builds.
An attacker sends a crafted serialized payload over the network to a vulnerable SharePoint endpoint. No authentication and no user interaction are required. When the server deserializes the payload, it executes attacker-controlled code, yielding full remote code execution on the SharePoint host. The impact covers confidentiality, integrity, and availability at the highest severity. The only precondition is network reachability to the SharePoint server. CISA added this vulnerability to the Known Exploited Vulnerabilities catalog, reflecting confirmed exploitation activity.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If Microsoft SharePoint runs inside your authorization boundary, yes — CVE-2026-58644 affects your FedRAMP authorization. CISA has listed this vulnerability in its Known Exploited Vulnerabilities catalog and set a remediation deadline of July 19, 2026. An unpatched Known Exploited Vulnerability inside your boundary is a finding: your assessor and sponsoring agency will expect it either remediated or formally documented with a mitigation before that date arrives.
Remediating Microsoft SharePoint is your responsibility under the FedRAMP shared-responsibility model — Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus Knox's automated continuous monitoring platform and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours; maintaining a compliant posture while you do it is not something you manage alone.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on a continuous basis. When something like CVE-2026-58644 surfaces, exposure is identified through ongoing monitoring rather than waiting for an assessor to flag it at a scheduled review.
Knox operates a FedRAMP-as-a-Service platform. The platform is pre-authorized at FedRAMP High. It spans AWS, Azure, and Google Cloud within a single boundary. Your application inherits 60–80% of the required security controls on day one. No agency sponsor is required to begin. Knox's automated continuous monitoring platform handles control mapping, vulnerability detection, and remediation after you go live. The result is FedRAMP in 90 days for 90% less, without the delays or dependencies that define the traditional route. Book a meeting and Knox maps your path to authorization.
If you miss the July 19, 2026 deadline, CVE-2026-58644 becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list turns a routine continuous-monitoring review into a hard conversation with your sponsoring agency. Meeting the deadline keeps your authorization intact.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.











_Horizontal_RGB.png)









