CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2736

As cited

Copy frozen at (site build).

vulnerabilities

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

CISA added CVE-2026-58644, a critical remote code execution vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog on Thursday. The flaw carries a CVSS score of 9.8 and involves a deserialization issue. Federal civilian agencies must patch the vulnerability by July 19, 2026.

Why it matters: Federal civilian executive branch agencies are mandated to remediate this critical SharePoint RCE by July 19, 2026, and private organizations running SharePoint Server should prioritize patching to prevent active exploitation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

CISA added CVE-2026-58644, a critical remote code execution vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog on Thursday. The flaw carries a CVSS score of 9.8 and involves a deserialization issue. Federal civilian agencies must patch the vulnerability by July 19, 2026.

Why it matters: Federal civilian executive branch agencies are mandated to remediate this critical SharePoint RCE by July 19, 2026, and private organizations running SharePoint Server should prioritize patching to prevent active exploitation.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary