CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026.

The vulnerability in question is CVE-2026-58644 (CVSS score: 9.8), a critical deserialization According to The Hacker News, the u.s. cybersecurity and infrastructure security agency (cisa) on thursday added a newly patched security flaw impacting microsoft sharepoint server to its known exploited vulnerabilities (kev) catalog, requiring federal civilian executive branch (fceb) agencies to apply the fixes by july 19, 2026.

the vulnerability in question is cve-2026-58644 (cvss score: 9.8), a critical deserialization. The development comes amid ongoing regulatory scrutiny in the sector. The Hacker News reports that this marks a significant milestone for the industry. The The Hacker News report provides additional context on the implications for market participants and regulatory frameworks moving forward.