Published Tuesday, July 21, 2026 at 08:52 PM PT

BLUF: CISA has added CVE-2026-58644, a remote code execution vulnerability in Microsoft SharePoint, to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. Any organization running affected SharePoint instances should assume compromise risk is elevated and prioritize assessment and patching immediately.
DETAILS
โข Vulnerability Confirmed: CVE-2026-58644 is a SharePoint RCE flaw. CISA KEV addition indicates exploitation has been observed beyond proof-of-concept.
โข Active Exploitation Reported: Multiple threat actors have begun targeting SharePoint deployments using this vulnerability. Exploitation capability is not theoretical or lab-only.
โข Escalating Trend: This is the third critical SharePoint RCE added to CISA KEV in recent months (CVE-2026-45659 and CVE-2026-50522 previously disclosed and actively exploited). Coordinated SharePoint targeting pattern suggests organized campaign.
โข CISA Hardening Guidance: CISA has issued SharePoint hardening recommendations in parallel, indicating this is part of a coordinated response to multiple related flaws in the same product line.
โข Scope Uncertain: Details on affected SharePoint versions, specific attack chain, and payload/post-exploitation capabilities are not yet fully disclosed in public sources. Microsoft advisory status and patch availability require verification.
IMPACT
Affected: Organizations running Microsoft SharePoint on-premises and potentially hybrid deployments. Cloud-only SharePoint Online exposure is not yet confirmed.
Threat Level: CRITICAL โ active exploitation + no known reliable mitigations short of patching or taking SharePoint offline.
Attack Surface: Unauthenticated or low-privilege access; exploitability likely high given CISA KEV status.
RECOMMENDED ACTIONS
Immediate Assessment (Today): Inventory all SharePoint deployments. Determine affected versions against Microsoft advisory (TBD โ check Microsoft Security Response Center).
Isolation Assessment (24โ48 hrs): If patch is not available, evaluate segmentation/WAF rules; consider taking affected instances offline if business impact is acceptable.
Log Review: Search SharePoint access/application logs for anomalous POST requests, unusual user-agent strings, or failed authentication spikes from the past 30 days.
Patch When Available: Microsoft will issue security updates. Prioritize deployment to all affected instances.
Monitor for PoC: Track public repositories and threat forums for working exploit code; assume it will surface within 24โ72 hours of KEV addition.
SOURCES
- CISA Known Exploited Vulnerabilities (KEV) catalog
- The Hacker News (summary aggregator of CISA alert)
- CISA Current Activity (hardening guidance issued concurrently)
Note: Details on patch timeline, exact affected versions, and post-exploitation behavior are not yet fully public. Monitor Microsoft Security Update Guide and CISA advisories for updates.
Recent high-severity events at publish time:

