CISA Adds Actively Exploited Microsoft SharePoint Flaw to KEV Catalog
A deserialization vulnerability in Microsoft SharePoint is currently being exploited in the wild, prompting an urgent remediation deadline for federal agencies.
CISA has added CVE-2026-58644, a deserialization of untrusted data vulnerability (CWE-502) affecting Microsoft SharePoint, to its Known Exploited Vulnerabilities catalog. This security flaw allows an unauthorized attacker to execute code over a network, posing a significant risk to affected environments.
Because the vulnerability is being actively exploited in real-world attacks, federal agencies are required to apply vendor-provided mitigations by July 19, 2026. Organizations must follow CISA's BOD 26-04 guidance, which includes evaluating internet exposure and adhering to specific forensics triage requirements.
Sources
- CISA KEV Original source
Continue Reading
FulcrumSec Claims Manchester Airport Breach, 86 GB Stolen
Extortion group FulcrumSec says it stole 86 GB from Manchester Airports Group, exposing detailed travel data.
Anthropic tackles Claude session hijacking via infostealers
Anthropic warns that infostealer malware is stealing Claude login sessions to drain accounts.
AI agents can be tricked into installing malware via unclaimed code packages
Researchers found 120 unregistered domains in AI documentation that could be hijacked to infect corporate networks.