CVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
Rapid7Archived Jul 17, 2026✓ Full text saved
Overview On July 14, 2026, Microsoft published a security advisory addressing CVE-2026-58644 , a critical remote code execution (RCE) vulnerability affecting on-premises Microsoft SharePoint Server deployments. The vulnerability, which carries a CVSS v3.1 score of 9.8 (Critical), results from the deserialization of untrusted data ( CWE-502 ) and allows an unauthenticated attacker to execute arbitrary code. Microsoft confirmed active exploitation of CVE-2026-58644, and the vulnerability was subse
Full text archived locally
✦ AI Summary· Claude Sonnet
OverviewOn July 14, 2026, Microsoft published a security advisory addressing CVE-2026-58644, a critical remote code execution (RCE) vulnerability affecting on-premises Microsoft SharePoint Server deployments. The vulnerability, which carries a CVSS v3.1 score of 9.8 (Critical), results from the deserialization of untrusted data (CWE-502) and allows an unauthenticated attacker to execute arbitrary code.Microsoft confirmed active exploitation of CVE-2026-58644, and the vulnerability was subsequently added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on July 16, 2026. In parallel, CISA published guidance recommending organizations immediately apply Microsoft’s security updates and leverage Microsoft Defender and AMSI detections to identify exploitation attempts.Affected products:Microsoft SharePoint Enterprise Server 2016Microsoft SharePoint Server 2019Microsoft SharePoint Server Subscription EditionMitigation guidanceOrganizations operating affected on-premises Microsoft SharePoint Server should prioritize remediation on an emergency basis.Microsoft’s recommendations:Apply the July 14, 2026 security updates for all affected SharePoint versions.Verify that security updates completed successfully across all SharePoint servers.Ensure Antimalware Scan Interface (AMSI) integration is enabled for every SharePoint web application.Monitor Microsoft Defender and AMSI detections for indicators of attempted exploitation.Initiate incident response procedures if exploitation artifacts are detected.Microsoft and CISA recommend monitoring for the following security detections associated with observed SharePoint exploitation activity.AMSI / Microsoft Defender detections:Exploit:Script/SuspSignoutReqBody.ARequest body scanningSharePoint Server Subscription EditionMicrosoft reports observed exploitation attempts are blocked by this signature.Exploit:Script/ToolPaneAuthBypass.ARequest header scanningApplies to SharePoint Server 2016, SharePoint Server 2019, and Subscription Edition.Exploit:Script/ToolPaneAuthBypassAt the time of publication, no public IP addresses, domains, URLs, or additional network-based indicators of compromise have been widely disclosed.Administrators should consult Microsoft’s advisory for the most current remediation guidance and update availability.Rapid7 customersExposure Command, InsightVM, and NexposeExposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-58644 with an authenticated vulnerability check available since the July 14 content release.UpdatesJuly 17, 2026: Initial publication.Article TagsEmergent Threat ResponseRapid7Author PostsRelated blog postsVulnerabilities and ExploitsRapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)Rapid7Vulnerabilities and ExploitsActive Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)Jonah BurgessVulnerabilities and ExploitsCVE-2026-10520, CVE-2026-10523 - Multiple critical vulnerabilities affecting Ivanti SentryRapid7Vulnerabilities and ExploitsCritical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)Rapid7See all posts