Critical Analysis: CVE-2026-58644 - Microsoft SharePoint Deserialization of Untrusted Data Vulne... — July 18, 2026
Published 18 Jul 2026 · vulnerability management, CVE analysis, threat intelligence, security operations, cybersecurity news
As a senior analyst at AGMP Partners, I’ve been tracking a critical SharePoint vulnerability, CVE-2026-58644, that Microsoft just dropped details on this week. This isn't just another patch Tuesday item; it's a deserialization of untrusted data flaw that, frankly, presents a significant headache for enterprise environments. The CVSSv3 score of 9.8 is no joke, designating it as Critical, and from what we've seen, that rating is absolutely justified. We're talking unauthenticated remote code execution (RCE) on potentially broad swathes of mission-critical infrastructure. My gut tells me this will be heavily weaponized in short order. Initial Discovery and Context The disclosure surfaced on July 18, 2026, and it immediately grabbed my attention. The vulnerability resides within Microsoft SharePoint Server, specifically targeting how it handles deserialization of certain data streams. From w