CRITICAL

CVE-2026-58644

Microsoft Sharepoint Server 2026-07-14 CVSS v3.1
CVSS
9.8
KEV

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Summary dbcve.org

Microsoft Office SharePoint contains a deserialization vulnerability where untrusted data is processed without proper validation, enabling an unauthenticated remote attacker to execute arbitrary code over the network.

Mitigation

Apply the latest Microsoft SharePoint security updates immediately to address the deserialization flaw and prevent remote code execution.

Patch Commit

Weakness (CWE)

CWE-502 Deserialization of Untrusted Data

EPSS Score

15.87%
Probability of exploitation in next 30 days
96.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE