M365 Change Tracker

← All changes · security · CVE-2026-58644

CVE-2026-58644CriticalImmediate

Microsoft SharePoint Remote Code Execution Vulnerability

Severity Critical  ·  Urgency Immediate  ·  Exploited in the wild

Why it matters: Exploited in the wild — CISA fix-by 2026-07-19

Remediate by Jul 19, 2026 · passed 36d ago

Remote Code Execution · Critical · CVSS 9.8 · Exploited in the wild. Affects: SharePoint Server.

CVSS 9.8EPSS 45.5%Exploited in the wildCISA remediation due 2026-07-19 (passed 36d ago)Security update published 2026-08-21Applies to On-premisesKB5002880NVDCISA KEV

Affected: SharePoint Server

Related changes

View at Microsoft →