Post
CRITICAL ⚡ MUST-KNOW

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

· rce · cve · zero-day · vulnerability

Microsoft SharePoint Server is affected by CVE-2026-58644 (CVSS 9.8), a critical deserialization flaw that allows remote, authenticated attackers to execute arbitrary code on the server. The vulnerability was exploited in the wild soon after disclosure. CISA has added it to the Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch agencies to apply the patch by July 19, 2026. Organizations running on-prem SharePoint Server should patch immediately regardless of federal deadline status.