CISA Alert: SharePoint RCE Zero-Day CVE-2026-58644 Patch Now! | Cybersecurity News (2026)

The recent addition of a critical vulnerability impacting Microsoft SharePoint Server to the Known Exploited Vulnerabilities (KEV) catalog by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) highlights the ongoing threat landscape in the digital realm. This particular flaw, identified as CVE-2026-58644, carries a CVSS score of 9.8, indicating its severe potential for exploitation. The vulnerability lies in a deserialization of untrusted data, enabling unauthorized attackers to execute arbitrary code on the SharePoint Server. What makes this issue particularly concerning is its remote exploitability over the internet, with low attack complexity. Microsoft's advisory emphasizes that an attacker, authenticated as a Site Owner, can inject and execute code remotely, posing a significant risk to organizations. The affected versions include Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, and Microsoft SharePoint Enterprise Server 2016. The vulnerability was patched as part of the July 14, 2026, Patch Tuesday updates, but it was already being weaponized as a zero-day exploit before the fixes were available. This highlights the importance of timely patching and the potential consequences of delayed responses to security threats. CISA's warning about active exploitation of multiple SharePoint Server vulnerabilities further underscores the urgency of addressing these issues. The agency recommends several hardening measures to mitigate the threat, such as applying the latest patches, enabling Antimalware Scan Interface (AMSI) integration, scanning for intrusion artifacts, and implementing tailored logging mechanisms. Additionally, CISA advises against exposing SharePoint Servers directly to the internet and provides guidance on blocking external access and restricting farm and database communications. The addition of vulnerabilities impacting Fortinet FortiSandbox to the KEV catalog further emphasizes the dynamic nature of cybersecurity threats. These vulnerabilities, CVE-2026-25089 and CVE-2026-39808, were also reported to be actively exploited, requiring federal agencies to update their instances by July 19, 2026. The KEV catalog serves as a critical resource for organizations to stay informed about known exploited vulnerabilities, enabling them to take proactive measures to enhance their cybersecurity posture. In conclusion, the recent additions to the KEV catalog underscore the importance of vigilance and proactive security measures in the face of evolving cyber threats. Organizations must remain vigilant, promptly apply patches, and implement recommended hardening techniques to safeguard their systems and data from potential exploitation.

CISA Alert: SharePoint RCE Zero-Day CVE-2026-58644 Patch Now! | Cybersecurity News (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Errol Quitzon

Last Updated:

Views: 6423

Rating: 4.9 / 5 (59 voted)

Reviews: 82% of readers found this page helpful

Author information

Name: Errol Quitzon

Birthday: 1993-04-02

Address: 70604 Haley Lane, Port Weldonside, TN 99233-0942

Phone: +9665282866296

Job: Product Retail Agent

Hobby: Computer programming, Horseback riding, Hooping, Dance, Ice skating, Backpacking, Rafting

Introduction: My name is Errol Quitzon, I am a fair, cute, fancy, clean, attractive, sparkling, kind person who loves writing and wants to share my knowledge and understanding with you.