HIGHVulnerability
Verified
Global

CISA KEV: Microsoft SharePoint — Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.

Analysis

Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. Added to CISA Known Exploited Vulnerabilities catalog on 2026-07-16. Remediation due: 2026-07-19.

Indicators of Compromise (1)

CVE (1)
CVE-2026-58644
Source Attribution

Originally published by CISA KEV on Jul 16, 2026. Verified by: CISA.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-103264 — Fleet versions before 4.87.0 contain an authentication bypass vulnerability in t...

Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthenticated attackers who know or guess these non-secret identifiers can authenticate as iOS/iPadOS hosts to read device data and trigger device-scoped actions including software installation and MDM migr

CVE-2026-103264
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-103255 — n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2...

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the Supabase node where the tableId parameter is inserted into request paths without validation. Attackers can exploit workflows binding tableId to untrusted input to traverse to Auth and Storage APIs using the administrative serviceRole key, bypassing Row Level Security

CVE-2026-103255
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-103248 — n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2...

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability in the Supabase node's Filters (String) mode that fails to escape field values. Attackers can inject filter expressions from untrusted input to read all table rows, update all records, or delete entire tables in a single request.

CVE-2026-103248
NIST NVD