CISA Urges Agencies to Patch Actively Exploited SharePoint Zero-Day
A critical SharePoint Server vulnerability, CVE-2026-58644, has been added to CISA's KEV catalog. Federal agencies must patch by July 19, 2026.
TL;DR
- CISA adds CVE-2026-58644 to its Known Exploited Vulnerabilities list.
- The flaw is a critical deserialization issue in Microsoft SharePoint Server.
- Exploitation could lead to remote code execution on affected servers.
- Federal agencies required to remediate by July 19, 2026.
- Organizations using SharePoint should prioritize patching immediately.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical zero-day vulnerability in Microsoft SharePoint Server, CVE-2026-58644, to its Known Exploited Vulnerabilities (KEV) catalog. With a CVSS severity score of 9.8, this flaw poses a significant risk to organizations still running unpatched versions of SharePoint.
CISA has mandated that all Federal Civilian Executive Branch (FCEB) agencies apply the necessary patches by July 19, 2026. Given the active exploitation of this vulnerability, enterprise IT and security teams managing SharePoint environments should treat this as a high-priority incident.
About CVE-2026-58644
- CVE-2026-58644 is a critical deserialization vulnerability in Microsoft SharePoint Server.
- It carries a CVSS base score of 9.8, indicating critical severity.
- Successful exploitation could allow an attacker to execute arbitrary code remotely.
- Microsoft released patches for this flaw prior to CISA’s KEV listing.
- The vulnerability affects on-premises installations of SharePoint Server.
What Organizations Should Do
- Immediately audit environments for affected SharePoint Server versions.
- Apply the official Microsoft patches released for CVE-2026-58644 without delay.
- Review network logs for signs of unauthorized access or exploitation attempts.
- Ensure third-party vendors and integrations using SharePoint are also notified.
- Consider implementing network segmentation and monitoring around SharePoint instances.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.