The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-58644, to its Known Exploited Vulnerabilities (KEV) catalog. The flaw, which carries a CVSS score of 9.8, is a deserialization of untrusted data vulnerability that allows an unauthenticated attacker to execute arbitrary code on affected SharePoint servers. Microsoft released patches for the vulnerability as part of its July 14, 2026 Patch Tuesday updates, and has confirmed that the flaw was exploited as a zero-day prior to the patch.
The vulnerability affects Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. CISA has mandated that Federal Civilian Executive Branch (FCEB) agencies apply the fixes by July 19, 2026. The agency also warned of active exploitation of multiple SharePoint Server vulnerabilities, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644, which could enable threat actors to gain unauthorized access to on-premises instances, steal Internet Information Services (IIS) machine keys, and deploy malware.
CISA has outlined several hardening measures to contain the threat, including applying the latest patches, verifying Antimalware Scan Interface (AMSI) integration, scanning for intrusion artifacts, establishing tailored logging, avoiding direct internet exposure of SharePoint Servers, and blocking external access to SharePoint Central Administration. Additionally, CISA added two critical flaws in Fortinet FortiSandbox (CVE-2026-25089 and CVE-2026-39808) to the KEV catalog.
CVEs: CVE-2026-58644, CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-25089, CVE-2026-39808
Companies: Microsoft, CISA, Fortinet
Products: Microsoft SharePoint Server, Fortinet FortiSandbox
Original source: thehackernews.com