the other SharePoint bug: a 9.8 that runs code with no login, already exploited and on CISA's list

Everyone focused on the SharePoint privilege-escalation zero-day. CVE-2026-58644 is worse: an unauthenticated deserialization flaw that runs code on…

Aliteq
Priya Nair · Software & Systems Editor

What you need to know

The flaw: deserialization of untrusted data (CWE-502) in SharePoint Server → unauthenticated remote code execution.

What you need to know

Distinct from the SharePoint EoP zero-day — this is the unauthenticated RCE, a different CVE.

What you need to know

Affected: SharePoint Server 2016, 2019, and Subscription Edition (specific builds below).

What you need to know

Actively exploited and on CISA KEV — the remediation deadline (July 19) has passed.

What you need to know

Fix: the July 2026 security update. On-prem only; SharePoint Online is Microsoft's to patch.

Aliteq

Read the full story

the other SharePoint bug: a 9.8 that runs code with no login, already exploited and on CISA's list

Read the full story on Aliteq