Breaking
SecurityDeveloping Story

CISA Adds Actively Exploited Microsoft SharePoint Flaw to KEV Catalog

A deserialization vulnerability in Microsoft SharePoint is currently being exploited in the wild, prompting an urgent remediation deadline for federal agencies.

··1 month ago·1 min read
man siting facing laptop
Photo by Clint Patterson on Unsplash

CISA has added CVE-2026-58644, a deserialization of untrusted data vulnerability (CWE-502) affecting Microsoft SharePoint, to its Known Exploited Vulnerabilities catalog. This security flaw allows an unauthorized attacker to execute code over a network, posing a significant risk to affected environments.

Because the vulnerability is being actively exploited in real-world attacks, federal agencies are required to apply vendor-provided mitigations by July 19, 2026. Organizations must follow CISA's BOD 26-04 guidance, which includes evaluating internet exposure and adhering to specific forensics triage requirements.

#cve-2026-58644#microsoft#sharepoint#deserialization#cisa

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories