S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Aug 30, 2026

CVE-2026-58644 Scanner

CVE-2026-58644 Scanner - Remote Code Execution (RCE) vulnerability in Microsoft SharePoint Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.1k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2026-58644
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.
Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Microsoft SharePoint Enterprise Server 2016by Microsoft
AFFECTED< 16.0.5556.1005SAFE ✓≥ 16.0.5556.1005
Microsoft SharePoint Server 2019by Microsoft
AFFECTED< 16.0.10417.20153SAFE ✓≥ 16.0.10417.20153
Microsoft SharePoint Server Subscription Editionby Microsoft
AFFECTED< 16.0.19725.20384SAFE ✓≥ 16.0.19725.20384
Updated Sep 2, 2026View on NVD →
Detail

Microsoft SharePoint Server is widely deployed in enterprise environments to facilitate collaboration, document management, and content management. It is used by organizations of various sizes to create and manage websites, manage information, and support team collaboration. The platform allows for easy deployment of updates, handling of a wide range of files and integration with various business applications. It is managed by IT professionals who ensure its proper functioning and secure configuration. This software plays a crucial role in the digital transformation of businesses, supporting remote work and business processes.

The Remote Code Execution (RCE) vulnerability in Microsoft SharePoint Server allows an attacker to execute arbitrary code with the permissions of the application pool identity. The vulnerability is located in the WS-Federation passive sign-in endpoint within SharePoint Server versions 2016, 2019, and Subscription Edition. This flaw arises from improper deserialization of the SecurityContextToken Cookie value in the wresult parameter without proper type checking. An attacker can exploit this issue by sending crafted WS-Federation tokens containing BinaryFormatter gadget chains to perform code execution. This vulnerability has been assigned a critical severity rating.

The vulnerability is specifically found in the SharePoint authentication module (SPFederationAuthenticationModuleV2), where it uses DeflateCookieTransform to decode and BinaryFormatter to deserialize the SecurityContextToken Cookie value. The vulnerable parameter is the 'wresult' in the /_trust/default.aspx endpoint. The SecurityContextToken does not undergo a proper sanity check on the type restrictions, allowing crafted tokens to be processed. An attacker can construct a specially crafted gadget chain, such as DataSet + LosFormatter + XamlAssemblyLoadFromFile, leading to code execution upon deserialization.

Exploitation of this vulnerability can lead to full compromise of the SharePoint farm, allowing attackers to gain unauthorized access and control over the environment. With elevated code execution, attackers may extract machine keys for persistent forged authentication tokens or move laterally within the domain. This potentially enables further system breaches, unauthorized data access, and a wide variety of malicious activities executed under the guise of legitimate SharePoint processes.

REFERENCES

Solution Advice
  • Apply the July 2026 Cumulative Update (KB5002882 / build 16.0.19725.20434 or later) to address the vulnerability.
  • Rotate SharePoint farm machine keys using Set-SPMachineKey or Update-SPMachineKey tools and perform IIS reset to revoke any compromised keys.
  • Implement AMSI request-body scanning specifically for the /_trust/default.aspx to enhance security as a preventive measure.
  • Regularly update and patch SharePoint Server installations to mitigate vulnerabilitiest.
  • Enhance monitoring of SharePoint Server environments for signs of compromise and unauthorized access attempts.
  • Consider deploying application whitelisting to prevent unauthorized code execution on critical systems.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.