CISA Adds Exploited SharePoint RCE Zero-Day to Known Vulnerabilities, Urges Immediate Patching
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security flaw in Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability, identified as CVE-2026-58644, allows unauthorized attackers to execute arbitrary code. CISA has mandated that Federal Civilian Executive Branch agencies apply the necessary patches by July 19, 2026. This vulnerability affects several versions of SharePoint Server, including the Subscription Edition, 2019, and 2016. Microsoft has released patches as part of its July 2026 Patch Tuesday updates. The flaw has been actively exploited, prompting CISA to issue hardening measures to mitigate the threat.