4:00PM, 17 July 2026
TLP Rating:
CVE-2026-58644 and CVE-2026-50522 affecting SharePoint Server
Two critical vulnerabilities in Microsoft SharePoint are under active exploitation.
Both CVE-2026-58644 and CVE-2026-50522 are deserialization of untrusted data vulnerabilities which can enable an unauthorised attacker to execute code over a network.
The NCSC encourages organisations in New Zealand that use affected versions of the products to review the vendor advisory and apply the remediation as soon as possible.
What's happening
Systems affected
CVE-2026-58644 affects the following products:
- Microsoft SharePoint Server 2019 16.0.0 before 16.0.10417.20153
- Microsoft SharePoint Enterprise Server 2016 16.0.0 before 16.0.5556.1005
- Microsoft SharePoint Server Subscription Edition 16.0.0 before 16.0.19725.20384
CVE-2026-50522 affects the following products:
- Microsoft SharePoint Server 2019 16.0.0 before 16.0.10417.20175
- Microsoft SharePoint Enterprise Server 2016 16.0.0 before 16.0.5561.1001
- Microsoft SharePoint Server Subscription Edition 16.0.0 before 16.0.19725.20434
What to do
Prevention
To prevent exploitation, update affected products to a patched version. If remediation or mitigation action cannot be undertaken immediately, then we recommend isolating SharePoint from the internet.
More information
Read more about this alert on the vendor website:
If you require more information or further support, submit a report on our website:
Report an incident