news.mlab.sh
Back to the feed
vulnerability

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

Critical
Summary

CISA has added a critical, actively exploited vulnerability in Microsoft SharePoint Server to its KEV list, forcing federal agencies to address it immediately. This zero-day flaw, CVE-2026-58644, allows for remote code execution and poses a significant risk to organizations using the affected software.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability, identified as CVE-2026-58644, is a critical deserialization vulnerability that allows an attacker to execute arbitrary code on a target system. This means a malicious actor could potentially gain full control of a SharePoint server, leading to data breaches, system compromise, and disruption of operations. The KEV listing mandates that all Federal Civilian Executive Branch (FCEB) agencies must apply the necessary patches by July 19, 2026, to mitigate this risk. The vulnerability stems from a flaw in how SharePoint handles serialized data, allowing attackers to craft malicious input that triggers the exploitation.

Read the full article at The Hacker News