CRITICAL ⚡ MUST-KNOW
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
CISA has added CVE-2026-58644, a critical (CVSS 9.8) deserialization vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The flaw allows unauthenticated remote code execution. Federal Civilian Executive Branch agencies must apply the fix by July 19, 2026, and any organization running on-prem SharePoint Server should treat this as urgent and patch immediately regardless of sector.