Published Tuesday, July 21, 2026 at 08:52 PM PT

<strong>CVE-2026-58644: Microsoft SharePoint RCE Added to CISA KEV โ€” Active Exploitation Confirmed</strong>


BLUF: CISA has added CVE-2026-58644, a remote code execution vulnerability in Microsoft SharePoint, to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. Any organization running affected SharePoint instances should assume compromise risk is elevated and prioritize assessment and patching immediately.


DETAILS

โ€ข Vulnerability Confirmed: CVE-2026-58644 is a SharePoint RCE flaw. CISA KEV addition indicates exploitation has been observed beyond proof-of-concept.

โ€ข Active Exploitation Reported: Multiple threat actors have begun targeting SharePoint deployments using this vulnerability. Exploitation capability is not theoretical or lab-only.

โ€ข Escalating Trend: This is the third critical SharePoint RCE added to CISA KEV in recent months (CVE-2026-45659 and CVE-2026-50522 previously disclosed and actively exploited). Coordinated SharePoint targeting pattern suggests organized campaign.

โ€ข CISA Hardening Guidance: CISA has issued SharePoint hardening recommendations in parallel, indicating this is part of a coordinated response to multiple related flaws in the same product line.

โ€ข Scope Uncertain: Details on affected SharePoint versions, specific attack chain, and payload/post-exploitation capabilities are not yet fully disclosed in public sources. Microsoft advisory status and patch availability require verification.


IMPACT

Affected: Organizations running Microsoft SharePoint on-premises and potentially hybrid deployments. Cloud-only SharePoint Online exposure is not yet confirmed.

Threat Level: CRITICAL โ€” active exploitation + no known reliable mitigations short of patching or taking SharePoint offline.

Attack Surface: Unauthenticated or low-privilege access; exploitability likely high given CISA KEV status.


RECOMMENDED ACTIONS

  1. Immediate Assessment (Today): Inventory all SharePoint deployments. Determine affected versions against Microsoft advisory (TBD โ€” check Microsoft Security Response Center).

  2. Isolation Assessment (24โ€“48 hrs): If patch is not available, evaluate segmentation/WAF rules; consider taking affected instances offline if business impact is acceptable.

  3. Log Review: Search SharePoint access/application logs for anomalous POST requests, unusual user-agent strings, or failed authentication spikes from the past 30 days.

  4. Patch When Available: Microsoft will issue security updates. Prioritize deployment to all affected instances.

  5. Monitor for PoC: Track public repositories and threat forums for working exploit code; assume it will surface within 24โ€“72 hours of KEV addition.


SOURCES

  • CISA Known Exploited Vulnerabilities (KEV) catalog
  • The Hacker News (summary aggregator of CISA alert)
  • CISA Current Activity (hardening guidance issued concurrently)

Note: Details on patch timeline, exact affected versions, and post-exploitation behavior are not yet fully public. Monitor Microsoft Security Update Guide and CISA advisories for updates.


Recent high-severity events at publish time:

Recent high-severity events