logo

CISA Warns of Microsoft SharePoint Code Execution Vulnerability Exploited in Attacks

ID: 8af2f8d6-4940-5ab2-9fe0-439d828b6d8a

STIX ID: report--8af2f8d6-4940-5ab2-9fe0-439d828b6d8a

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

Author: Abinaya

...
...

CISA has added CVE-2026-58644 — an unsafe deserialization vulnerability in Microsoft SharePoint that allows unauthenticated remote code execution — to its Known Exploited Vulnerabilities catalog after confirming active exploitation; organizations (especially internet-facing SharePoint instances and federal agencies subject to BOD 26-04) are urged to apply Microsoft patches or mitigations, review for indicators of compromise such as web shells and unusual activity, and restrict external access until protections are in place.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.