CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
Read original article ↗AI Summary
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the actively exploited SharePoint Server remote code execution vulnerability CVE-2026-58644 to its Known Exploited Vulnerabilities (KEV) catalog. This critical zero-day flaw allows authenticated attackers with Site Owner privileges to execute arbitrary code remotely on vulnerable SharePoint servers. CISA warns of ongoing exploitation and mandates federal agencies to apply patches by July 19, 2026. Additional SharePoint-related vulnerabilities are also being actively exploited, enabling remote code execution and post-exploitation activities such as theft of IIS machine keys.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.