17 July 2026
Reference: CVE-2026-58644
1. What is being reported?
The issue involves Microsoft SharePoint improperly handling certain data it receives, allowing attackers to run malicious software on the system without permission. This is called 'deserialization of untrusted data' and it can be exploited over a network, meaning attackers do not need physical access.
2. What this means in plain English
If your organisation uses Microsoft SharePoint, this vulnerability could let hackers take control of your SharePoint server remotely. This could lead to data theft, disruption of services, or further attacks on your network. Because it is actively being exploited, the risk is urgent.
3. Could this affect a small business?
Small businesses or charities that use Microsoft SharePoint, especially if it is accessible from the internet, are at risk. If you do not use SharePoint or your SharePoint is not exposed online, you are less likely to be affected. However, it is important to check with your IT provider.
4. What to do now
- Contact your IT provider or software supplier immediately to confirm if your SharePoint system is affected.
- Apply any security updates or patches provided by Microsoft as soon as they are available.
- If patches are not yet available, follow any recommended mitigations from Microsoft or your IT provider to reduce risk.
- Review your SharePoint system’s internet exposure and consider restricting access until the issue is resolved.
5. Ask your IT provider
Can you confirm whether our Microsoft SharePoint system is affected by CVE-2026-58644 and what steps are being taken to protect us?
6. Bottom line
If you use Microsoft SharePoint, act quickly to ensure it is patched or protected against this critical vulnerability to avoid serious security risks.
Information based on CISA KEV, NVD and multiple reputable security reports.