Security & Threat Intelligence · 25.07.2026, 15:30 UTC
CVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
| Schweregrad | critical aktiv ausgenutzt (KEV) |
|---|---|
| CVSS | 9.8 |
| CVE | ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | Rapid7 Blog ↗ |
| Veröffentlicht | 25.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad kritisch (CVSS 9.8). Sie wird laut CISA-KEV aktiv ausgenutzt und sollte priorisiert behandelt werden. Betroffene Kennungen: CVE-2026-58644. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
OverviewOn July 14, 2026, Microsoft published a security advisory addressing CVE-2026-58644, a critical remote code execution (RCE) vulnerability affecting on-premises Microsoft SharePoint Server deployments. The vulnerability, which carries a CVSS v3.1 score of 9.8 (Critical), results from the deserialization of untrusted data (CWE-502) and allows an unauthenticated attacker to execute arbitrary code.Microsoft confirmed active exploitation of CVE-2026-58644, and the vulnerability was subsequently added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on July 16, 2026. In parallel, CISA published guidance recommending organizations immediately apply Microsoft’s security updates and leverage Microsoft Defender and AMSI detections to identify exploitation attempts.Affected products:Microsoft SharePoint Enterprise Server 2016Microsoft SharePoint Server 2019Microsoft SharePoint Server Subscription EditionMitigation guidanceOrganizations operating affected on-premises Microsoft SharePoint Server should prioritize remediation on an emergency basis.Microsoft’s recommendations:Apply the July 14, 2026 security updates for all affected SharePoint versions.Verify that security updates completed successfully across all SharePoint servers.Ensure Antimalware Scan Interface (AMSI) integration is enabled for every SharePoint web application.Monitor Microsoft Defender and AMSI detections for indicators of attempted exploitation.Initiate incident response procedures if exploitation artifacts are detected.Microsoft and CISA recommend monitoring for the following security detections …