CVE Tools

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

The Hacker NewsBy The Hacker News

Reported exploitedSharePoint Server Subscription EditionSharePoint Server 2019

Our summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability affecting Microsoft SharePoint Server to its list of known exploited vulnerabilities. The flaw, tracked as CVE-2026-58644, allows attackers with site owner privileges to execute arbitrary code remotely. Patches were issued on July 14, 2026, but the vulnerability had already been actively exploited before fixes became available. Affected products include SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. CISA urges organizations to apply updates immediately to prevent potential breaches.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store