CRITICAL
CVE-2026-58644
CVSS
9.8
KEV
Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Summary dbcve.org
Microsoft Office SharePoint contains a deserialization vulnerability where untrusted data is processed without proper validation, enabling an unauthenticated remote attacker to execute arbitrary code over the network.
Mitigation
Apply the latest Microsoft SharePoint security updates immediately to address the deserialization flaw and prevent remote code execution.
Weakness (CWE)
CWE-502
Deserialization of Untrusted Data
EPSS Score
15.87%
Probability of exploitation in next 30 days
96.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.