CVE-2026-58644 · High · CISA KEV
Microsoft SharePoint Deserialization Flaw: Remote Code Execution Risk
Threat Engine Auto-Feed · data current as of 2026-07-17
A deserialization of untrusted data vulnerability in Microsoft SharePoint allows an unauthorized attacker to execute code remotely. This flaw is listed in CISA KEV, indicating active exploitation in the wild, and has a high exploitation pressure score.
- CVSS:
- EPSS percentile: 0.70721
- Exploitation pressure: 67/100 (High)
Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 71th percentile. Threat × Vulnerability from public signals — impact depends on your environment.
Weakness —
This vulnerability involves 'deserialization of untrusted data,' meaning the software processes data from an external source without properly validating its structure or content. An attacker can craft malicious data that, when deserialized by the application, tricks it into executing arbitrary code.
Who's at risk
Exposure: unknown · Auth: unknown · unknown
Enterprise profiles most at risk
- Organizations heavily reliant on Microsoft SharePoint for collaboration and data management
- Financial services organizations (due to assessed adversary targeting)
- Technology sector organizations (due to assessed adversary targeting)
Misconfigurations that escalate it
- SharePoint instances exposed to untrusted networks or the internet without robust access controls
- Lack of strict input validation on data processed by SharePoint
High-impact scenarios
- Unauthorized remote code execution on SharePoint servers, leading to full system compromise
- Data exfiltration or manipulation from SharePoint repositories
- Establishment of persistent access within the enterprise network, potentially leading to broader compromise
Likely adversaries
- FIN7 — Financial services (Assessed)
- LockBit affiliates — Financial services (Assessed)
- APT38 (Lazarus) — Financial services (Assessed)
- APT29 (Cozy Bear) — Technology (Assessed)
- Scattered Spider — Technology (Assessed)
What to do (defensive)
Detect
- Monitor SharePoint server logs for unusual process execution or network activity originating from SharePoint services
- Implement network segmentation to limit communication paths to and from SharePoint servers
- Utilize endpoint detection and response (EDR) solutions on SharePoint servers to detect anomalous behavior
Contain
- Isolate affected SharePoint servers from the network if compromise is suspected
- Restrict network access to SharePoint services to only necessary internal systems and users
Patch
- Apply the latest security updates and patches from Microsoft for SharePoint immediately
Frontier verdict — High
This is a critical vulnerability in Microsoft SharePoint, actively exploited in the wild, enabling remote code execution and requiring immediate patching.
For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.