CVE-2026-58644 · High · CISA KEV

Microsoft SharePoint Deserialization Flaw: Remote Code Execution Risk

Threat Engine Auto-Feed · data current as of 2026-07-17

A deserialization of untrusted data vulnerability in Microsoft SharePoint allows an unauthorized attacker to execute code remotely. This flaw is listed in CISA KEV, indicating active exploitation in the wild, and has a high exploitation pressure score.

  • CVSS:
  • EPSS percentile: 0.70721
  • Exploitation pressure: 67/100 (High)

Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 71th percentile. Threat × Vulnerability from public signals — impact depends on your environment.

Weakness —

This vulnerability involves 'deserialization of untrusted data,' meaning the software processes data from an external source without properly validating its structure or content. An attacker can craft malicious data that, when deserialized by the application, tricks it into executing arbitrary code.

Who's at risk

Exposure: unknown · Auth: unknown · unknown

Enterprise profiles most at risk

  • Organizations heavily reliant on Microsoft SharePoint for collaboration and data management
  • Financial services organizations (due to assessed adversary targeting)
  • Technology sector organizations (due to assessed adversary targeting)

Misconfigurations that escalate it

  • SharePoint instances exposed to untrusted networks or the internet without robust access controls
  • Lack of strict input validation on data processed by SharePoint

High-impact scenarios

  • Unauthorized remote code execution on SharePoint servers, leading to full system compromise
  • Data exfiltration or manipulation from SharePoint repositories
  • Establishment of persistent access within the enterprise network, potentially leading to broader compromise

Likely adversaries

  • FIN7 — Financial services (Assessed)
  • LockBit affiliates — Financial services (Assessed)
  • APT38 (Lazarus) — Financial services (Assessed)
  • APT29 (Cozy Bear) — Technology (Assessed)
  • Scattered Spider — Technology (Assessed)

What to do (defensive)

Detect

  • Monitor SharePoint server logs for unusual process execution or network activity originating from SharePoint services
  • Implement network segmentation to limit communication paths to and from SharePoint servers
  • Utilize endpoint detection and response (EDR) solutions on SharePoint servers to detect anomalous behavior

Contain

  • Isolate affected SharePoint servers from the network if compromise is suspected
  • Restrict network access to SharePoint services to only necessary internal systems and users

Patch

  • Apply the latest security updates and patches from Microsoft for SharePoint immediately

Frontier verdict — High

This is a critical vulnerability in Microsoft SharePoint, actively exploited in the wild, enabling remote code execution and requiring immediate patching.

For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.