logo

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

ID: 2d231dbf-6624-5fe5-a813-545d622c07f5

STIX ID: report--2d231dbf-6624-5fe5-a813-545d622c07f5

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

Author: [email protected] (The Hacker News)

...
...

CISA added a critical SharePoint deserialization vulnerability (CVE-2026-58644, CVSS 9.8) — exploitable remotely and confirmed as exploited in the wild — to its Known Exploited Vulnerabilities catalog, requiring federal agencies to apply Microsoft’s July 14, 2026 patches by July 19, 2026; the advisory highlights risk of RCE, post‑exploitation actions (including IIS machine key theft), and prescribes hardening and patching steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.