CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◆ Security Tools & Reviews Jul 17, 2026

CVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild

Rapid7 Archived Jul 17, 2026 ✓ Full text saved

Overview On July 14, 2026, Microsoft published a security advisory addressing CVE-2026-58644 , a critical remote code execution (RCE) vulnerability affecting on-premises Microsoft SharePoint Server deployments. The vulnerability, which carries a CVSS v3.1 score of 9.8 (Critical), results from the deserialization of untrusted data ( CWE-502 ) and allows an unauthenticated attacker to execute arbitrary code. Microsoft confirmed active exploitation of CVE-2026-58644, and the vulnerability was subse

Full text archived locally
✦ AI Summary · Claude Sonnet


    OverviewOn July 14, 2026, Microsoft published a security advisory addressing CVE-2026-58644, a critical remote code execution (RCE) vulnerability affecting on-premises Microsoft SharePoint Server deployments. The vulnerability, which carries a CVSS v3.1 score of 9.8 (Critical), results from the deserialization of untrusted data (CWE-502) and allows an unauthenticated attacker to execute arbitrary code.Microsoft confirmed active exploitation of CVE-2026-58644, and the vulnerability was subsequently added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on July 16, 2026. In parallel, CISA published guidance recommending organizations immediately apply Microsoft’s security updates and leverage Microsoft Defender and AMSI detections to identify exploitation attempts.Affected products:Microsoft SharePoint Enterprise Server 2016Microsoft SharePoint Server 2019Microsoft SharePoint Server Subscription EditionMitigation guidanceOrganizations operating affected on-premises Microsoft SharePoint Server should prioritize remediation on an emergency basis.Microsoft’s recommendations:Apply the July 14, 2026 security updates for all affected SharePoint versions.Verify that security updates completed successfully across all SharePoint servers.Ensure Antimalware Scan Interface (AMSI) integration is enabled for every SharePoint web application.Monitor Microsoft Defender and AMSI detections for indicators of attempted exploitation.Initiate incident response procedures if exploitation artifacts are detected.Microsoft and CISA recommend monitoring for the following security detections associated with observed SharePoint exploitation activity.AMSI / Microsoft Defender detections:Exploit:Script/SuspSignoutReqBody.ARequest body scanningSharePoint Server Subscription EditionMicrosoft reports observed exploitation attempts are blocked by this signature.Exploit:Script/ToolPaneAuthBypass.ARequest header scanningApplies to SharePoint Server 2016, SharePoint Server 2019, and Subscription Edition.Exploit:Script/ToolPaneAuthBypassAt the time of publication, no public IP addresses, domains, URLs, or additional network-based indicators of compromise have been widely disclosed.Administrators should consult Microsoft’s advisory for the most current remediation guidance and update availability.Rapid7 customersExposure Command, InsightVM, and NexposeExposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-58644 with an authenticated vulnerability check available since the July 14 content release.UpdatesJuly 17, 2026: Initial publication.Article TagsEmergent Threat ResponseRapid7Author PostsRelated blog postsVulnerabilities and ExploitsRapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)Rapid7Vulnerabilities and ExploitsActive Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)Jonah BurgessVulnerabilities and ExploitsCVE-2026-10520, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti SentryRapid7Vulnerabilities and ExploitsCritical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)Rapid7See all posts
    💬 Team Notes
    Article Info
    Source
    Rapid7
    Category
    ◆ Security Tools & Reviews
    Published
    Jul 17, 2026
    Archived
    Jul 17, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗