Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical Microsoft SharePoint Vulnerability Could Allow Remote Attacks

A serious security flaw has been found in Microsoft SharePoint that lets attackers run harmful code remotely. This vulnerability is actively being exploited and has been officially recognised as a high risk by US and security agencies, meaning organisations using SharePoint need to act quickly to protect themselves.

17 July 2026

Reference: CVE-2026-58644

1. What is being reported?

The issue involves Microsoft SharePoint improperly handling certain data it receives, allowing attackers to run malicious software on the system without permission. This is called 'deserialization of untrusted data' and it can be exploited over a network, meaning attackers do not need physical access.

2. What this means in plain English

If your organisation uses Microsoft SharePoint, this vulnerability could let hackers take control of your SharePoint server remotely. This could lead to data theft, disruption of services, or further attacks on your network. Because it is actively being exploited, the risk is urgent.

3. Could this affect a small business?

Small businesses or charities that use Microsoft SharePoint, especially if it is accessible from the internet, are at risk. If you do not use SharePoint or your SharePoint is not exposed online, you are less likely to be affected. However, it is important to check with your IT provider.

4. What to do now

  • Contact your IT provider or software supplier immediately to confirm if your SharePoint system is affected.
  • Apply any security updates or patches provided by Microsoft as soon as they are available.
  • If patches are not yet available, follow any recommended mitigations from Microsoft or your IT provider to reduce risk.
  • Review your SharePoint system’s internet exposure and consider restricting access until the issue is resolved.

5. Ask your IT provider

Can you confirm whether our Microsoft SharePoint system is affected by CVE-2026-58644 and what steps are being taken to protect us?

6. Bottom line

If you use Microsoft SharePoint, act quickly to ensure it is patched or protected against this critical vulnerability to avoid serious security risks.

Information based on CISA KEV, NVD and multiple reputable security reports.

Back to Vulnerability Briefs