news.mlab.sh
Back to the feed
vulnerability

Fresh SharePoint Vulnerability Exploited Soon After Disclosure

Critical
Summary

A critical remote code execution vulnerability in Microsoft SharePoint has been actively exploited by threat actors shortly after its disclosure. Microsoft has released patches to address the issue, but CISA has added it to its list of known exploited vulnerabilities, urging federal agencies to prioritize patching.

A critical remote code execution (RCE) vulnerability in Microsoft SharePoint has been exploited by threat actors following its public disclosure. Tracked as CVE-2026-58644 and addressed through Microsoft’s July 2026 Patch Tuesday updates, this flaw stems from a deserialization of untrusted data. According to Microsoft, an attacker with Site Owner privileges could remotely inject and execute code on the SharePoint Server via a network-based attack. Microsoft’s security updates also resolved other SharePoint defects, including CVE-2026-56164, which was previously exploited as a zero-day, and CVE-2026-55040, a critical security bypass. CISA added CVE-2026-58644 to its Known Exploited Vulnerabilities (KEV) catalog on Thursday, two days after issuing the initial warning, and mandated patching within three days in line with BOD 26-04. Furthermore, CISA added CVE-2026-25089 and CVE-2026-39808, OS command injection flaws in Fortinet FortiSandbox, which were patched in June and April respectively, and were subsequently flagged as exploited in the wild by Defused intelligence. These vulnerabilities allow attackers to execute arbitrary code or commands on vulnerable appliances. Federal agencies are required to patch these three exploited bugs within three days.

Read the full article at SecurityWeek