Skip to content

CISA Registers Exploited SharePoint RCE as Known Vulnerability

At a glance: CVE-2026-58644 (CVSS 9.8) in SharePoint Server is actively being exploited and mandates patching for U.S. federal agencies by a set deadline.

CISA has added CVE-2026-58644 to its Catalog of Known Exploited Vulnerabilities. The critical deserialization flaw in Microsoft SharePoint Server requires U.S. federal agencies to remediate by 19 July 2026.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-58644 to its Catalog of Known Exploited Vulnerabilities (KEV) on Thursday. The vulnerability affects Microsoft SharePoint Server and carries a CVSS rating of 9.8 — it is already being exploited in the wild.

For U.S. Federal Civilian Executive Branch (FCEB) agencies, a mandatory patching deadline of 19 July 2026 applies. Inclusion in the KEV catalog signals that this vulnerability is actively being leveraged by threat actors and must be treated as the highest priority.

The security flaw enables remote code execution through unsafe deserialization. CISOs should prioritize remediation in environments running SharePoint Server instances — particularly in critical infrastructure — and verify patch availability from Microsoft.


Source: thehackernews.com · Published 17 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.

Share on: