← Back to browse · API

CVE-2026-58644

Severity
HIGH
CVSS
8.0
EPSS
0.05985
Risk score
59.09
CISA KEV
Yes
PoC
Yes
Published
2026-07-17
Modified
2026-07-17
First seen
2026-08-07
Aliases
CNVD-2026-27933, EUVD-2026-43779, GHSA-Q6CQ-5QPF-Q237
Products
Microsoft Microsoft SharePoint Enterprise Server 2016, Microsoft Microsoft SharePoint Server 2019, Microsoft Microsoft SharePoint Server Subscription Edition, Microsoft:Microsoft SharePoint Enterprise Server 2016 16.0.0 <16.0.5556.1005, Microsoft:Microsoft SharePoint Server 2019 16.0.0 <16.0.10417.20153, Microsoft:Microsoft SharePoint Server Subscription Edition 16.0.0 <16.0.19725.20384, Microsoft:SharePoint
Sources
cisa.gov CVE-2026-58644
euvd EUVD-2026-43779
github c7c3465edcecdbebb6c2ef34|CVE-2026-58644
cnvd CNVD-2026-27933

Description

Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are enterprise-level content management and collaboration platforms. A remote code execution vulnerability exists in Microsoft Office SharePoint. The vulnerability results from improper deserialization of untrusted data. An attacker can exploit this vulnerability to execute arbitrary code over the network.

References