
CISA adds exploited SharePoint remote-code flaw to emergency patch catalog
CISA added exploited Microsoft SharePoint flaw CVE-2026-58644 to its KEV catalog, urging rapid mitigation for on-prem servers.
CISA has added a newly exploited Microsoft SharePoint vulnerability, CVE-2026-58644, to its Known Exploited Vulnerabilities catalog, escalating pressure on administrators running on-premises SharePoint systems to move quickly. The agency says the flaw is a deserialization of untrusted data issue that can let an unauthorized attacker execute code over a network.
The addition matters because SharePoint remains a high-value enterprise target: it often sits close to document stores, identity plumbing, internal portals, and workflow systems. CISA's catalog entry lists Microsoft as the affected vendor, identifies the product as SharePoint, and gives federal civilian agencies a July 19 deadline to apply mitigations under Binding Operational Directive 26-04. That short timeline reflects the agency's view that active exploitation changes patching from routine maintenance into incident-prevention work.
Why administrators should treat it as urgent
The new catalog entry follows other SharePoint Server vulnerabilities that CISA has highlighted this month, including CVE-2026-56164, CVE-2026-45659, and CVE-2026-32201. The Hacker News reported that CISA warned of active exploitation involving several SharePoint Server bugs that could support remote code execution and post-exploitation activity, including attempts to steal Internet Information Services machine keys and use deserialization techniques for persistence.
Microsoft's Security Response Center page is the vendor reference for CVE-2026-58644, while CISA's catalog points agencies and other defenders back to vendor instructions, forensic triage requirements, and BOD 26-04 guidance. Organizations outside the U.S. government are not bound by that directive, but the KEV catalog is widely used as a practical priority list because entries require evidence of exploitation rather than theoretical risk alone.
What teams can do now
- Inventory internet-facing and internally exposed SharePoint servers, including older farms and test instances.
- Apply Microsoft's recommended updates or mitigations for CVE-2026-58644 and review related July SharePoint advisories.
- Check IIS logs, SharePoint logs, and endpoint telemetry for signs of suspicious deserialization activity, web shell deployment, or unexpected access to machine-key material.
- Limit unnecessary network exposure while patching and confirm that backups, recovery plans, and incident-response contacts are current.
The clearest takeaway is that on-premises SharePoint remains a recurring attacker focus. The combination of active exploitation, remote code execution potential, and CISA's emergency-style deadline makes this a patch-now item rather than a wait-for-the-next-maintenance-window issue.
Sources
Cover photo by Brett Sayles on Pexels, used under the Pexels License.
CyberOGZ Team






Comments (0)
Leave a Comment