Critical Analysis: CVE-2026-58644 - Microsoft SharePoint Deserialization of Untrusted Data Vulne... — July 21, 2026

Published 21 Jul 2026 · vulnerability management, CVE analysis, threat intelligence, security operations, cybersecurity news

AGMP Partners Initial Discovery and Context Alright, let’s get straight into the nitty-gritty of CVE-2026-58644, published just yesterday, July 21, 2026. This isn't just another vulnerability; it’s a critical unauthenticated remote code execution (RCE) flaw impacting Microsoft SharePoint, rated 9.8 CVSSv3.1. When I first saw the advisory drop, my immediate thought was, "Here we go again, another SharePoint deserialization vulnerability." It seems that despite Microsoft's consistent efforts, the deserialization attack surface in their enterprise products remains a persistent headache, offering a fertile ground for high-impact RCE vectors. The vulnerability was privately reported by a researcher, making me wonder how long it was actively exploited in the wild before discovery, a question that will undoubtedly be a focus for our threat hunting teams in the coming weeks. The core issue lies