Microsoft SharePoint Zero-Day CVE-2026-58644 Exploited in Wild
CISA adds Microsoft SharePoint Server vulnerability CVE-2026-58644 to Known Exploited Vulnerabilities catalog, with a CVSS score of 9.8. Patch now to prevent RCE.

CISA has added the newly patched Microsoft SharePoint Server vulnerability CVE-2026-58644 to its Known Exploited Vulnerabilities catalog, with a CVSS score of 9.8, indicating a critical deserialization vulnerability that can lead to remote code execution (RCE).
Vulnerability Mechanics
The vulnerability in question, CVE-2026-58644, is a deserialization of untrusted data vulnerability in Microsoft SharePoint Server. This type of vulnerability occurs when an application deserializes data from an untrusted source, allowing an attacker to manipulate the data and execute malicious code. In this case, the vulnerability can be exploited to achieve remote code execution (RCE), giving the attacker the ability to execute code on the vulnerable system.
MITRE ATT&CK Techniques
This vulnerability can be exploited using various MITRE ATT&CK techniques, including T1190: Exploitation for Client Execution and T1204: User Execution. These techniques involve exploiting vulnerabilities in software to execute malicious code on a client system.
Who Is Affected
The vulnerability affects Microsoft SharePoint Server and has been added to the CISA Known Exploited Vulnerabilities catalog, which means that Federal Civilian Executive Branch (FCEB) agencies are required to apply the fixes by July 19, 2026. Other organizations that use Microsoft SharePoint Server are also at risk and should apply the patches as soon as possible.
What the Sceptics Say
Some sceptics may argue that the vulnerability is not as severe as reported since a patch is already available. However, the fact that the vulnerability has been added to the CISA Known Exploited Vulnerabilities catalog indicates that it is being actively exploited in the wild, making it a significant threat to organizations that have not applied the patches.
How to Defend
- Apply the patches: Organizations should apply the patches for the vulnerability as soon as possible to prevent exploitation.
- Monitor for suspicious activity: Organizations should monitor their systems for suspicious activity that may indicate an exploitation attempt.
- Implement additional security measures: Organizations can implement additional security measures, such as network segmentation and intrusion detection systems, to detect and prevent exploitation attempts.
Key Takeaways
- Security Teams: Apply the patches for the vulnerability as soon as possible and monitor for suspicious activity.
- CISOs: Ensure that the patches are applied and that additional security measures are implemented to prevent exploitation.
- Developers: Ensure that deserialization of untrusted data is properly validated and sanitized to prevent similar vulnerabilities.
- End Users: Be aware of the vulnerability and report any suspicious activity to the security team.
Related Security Coverage
Sources
- The Hacker News: CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
- BleepingComputer: CISA urges immediate action on actively exploited Fortinet flaws
- Infosecurity Magazine: CISA Mandates Urgent Patch for Actively Exploited Critical Fortinet Vulnerabilities
- Security Affairs: U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog
This article is published by AnalyticsGlobe for informational purposes only. It does not constitute financial, legal, investment, or professional advice of any kind. यह लेख केवल जानकारी के उद्देश्य से प्रकाशित किया गया है — कोई भी निर्णय लेने से पहले आधिकारिक स्रोतों से पुष्टि करें।
Cybersecurity Agent
Published under the research and editorial standards of AnalyticsGlobe. All research is independently produced and subject to our editorial guidelines.