Back to Blog
CVE-2026-58644: Microsoft SharePoint — Remote Code Execution Risk (June 2026)
vulnerabilities

CVE-2026-58644: Microsoft SharePoint — Remote Code Execution Risk (June 2026)

breachwire TeamJul 19, 20262 min read

CVE-2026-58644 — Microsoft SharePoint

CVE-2026-58644 is a critical vulnerability in Microsoft SharePoint that enables remote, authenticated attackers to execute arbitrary code on affected servers. The flaw, rated critical and now actively exploited in the wild, was disclosed and patched in June 2026. CISA has added it to the Known Exploited Vulnerabilities catalog, requiring immediate remediation.

Attack Vector

Attackers must possess at least Site Owner privileges to exploit CVE-2026-58644. With these permissions, a remote attacker can send crafted requests to vulnerable SharePoint servers, triggering arbitrary code execution under the context of the SharePoint service. No public proof-of-concept is required for exploitation, and exploitation has already been observed in the wild. No specific IOCs have been published, but organizations should monitor for unusual activity from privileged SharePoint accounts.

Who Is at Risk

All organizations running unpatched Microsoft SharePoint servers are at risk, with confirmed exploitation targeting North American entities. The vulnerability affects Microsoft SharePoint deployments where users have Site Owner privileges. Microsoft is the primary affected vendor, and federal agencies have been explicitly mandated to patch immediately.

Patch & Mitigate

  • Patch: Apply the official Microsoft security update for CVE-2026-58644 released June 2026. CISA mandates immediate patching for federal agencies.
  • Workaround: No viable workaround is available; patching is the only effective mitigation.
  • Detect: Monitor audit logs for unexpected activity from Site Owner accounts, such as unusual process launches or configuration changes. Review network traffic for anomalous requests to SharePoint endpoints.

MITRE ATT&CK

  • TA0001 — Initial Access: Attackers leverage valid credentials with Site Owner privileges to gain a foothold.
  • TA0007 — Discovery: Post-exploitation, attackers may enumerate internal resources or sensitive data.
  • TA0009 — Collection: Compromised SharePoint servers can be used to collect confidential documents and data.

Source: https://www.securityweek.com/fresh-sharepoint-vulnerability-exploited-soon-after-disclosure/

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: