CISA adds exploited Microsoft SharePoint zero-day CVE-2026-58644 to KEV catalog

CISA says a newly tracked Microsoft SharePoint server flaw is already being used in real attacks, putting organizations with exposed SharePoint systems at immediate risk. The agency added CVE-2026-58644, a remote-code-execution vulnerability, to its Known Exploited Vulnerabilities catalog, meaning attackers can run code on vulnerable servers; the article indicates active exploitation but the provided text does not include affected versions or patch details.
Why it matters: Organizations running SharePoint should treat this as urgent because attackers are already exploiting it in the wild. Defenders should identify exposed SharePoint servers, apply Microsoft fixes or mitigations as soon as available, and hunt for signs of compromise immediately.

Sources

Attackers target critical FortiSandbox flaws as CISA issues patch order
2026.07.17 28% relevant
The article briefly notes the same CISA KEV update also included SharePoint flaw CVE-2026-58644, but that is secondary context rather than the main focus of this piece.
Fresh SharePoint Vulnerability Exploited Soon After Disclosure
Ionut Arghire 2026.07.17 96% relevant
This article directly updates the same event by reporting that Microsoft revised its advisory to mark CVE-2026-58644 as exploited after disclosure and that CISA added it to KEV with a three-day federal patch deadline. It also adds technical detail that the flaw is a deserialization issue enabling remote code execution by an authenticated Site Owner on SharePoint Server.
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
info@thehackernews.com (The Hacker News) 2026.07.17 100% relevant
This establishes a distinct tracked story because the concrete underlying event is CISA's KEV addition for a different SharePoint CVE, CVE-2026-58644, not the already tracked CVE-2026-45659 event.
← Back to all stories