CISA Adds Microsoft SharePoint Deserialization Flaw to KEV Catalog
A critical deserialization vulnerability in Microsoft SharePoint is currently being exploited in the wild, requiring immediate action from federal agencies.
The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-58644 to its Known Exploited Vulnerabilities catalog. This flaw, identified as a deserialization of untrusted data vulnerability (CWE-502), allows an unauthorized attacker to execute code over a network.
CISA has confirmed that this vulnerability is being actively exploited in real-world scenarios. Federal agencies are required to apply necessary mitigations by July 19, 2026, in accordance with BOD 26-04. Stakeholders should evaluate the internet exposure of their assets and follow vendor instructions to secure their environments, or discontinue use of the product if mitigations are unavailable.
Sources
- CISA KEV Original source
Continue Reading
FulcrumSec Claims Manchester Airport Breach, 86 GB Stolen
Extortion group FulcrumSec says it stole 86 GB from Manchester Airports Group, exposing detailed travel data.
Anthropic tackles Claude session hijacking via infostealers
Anthropic warns that infostealer malware is stealing Claude login sessions to drain accounts.
AI agents can be tricked into installing malware via unclaimed code packages
Researchers found 120 unregistered domains in AI documentation that could be hijacked to infect corporate networks.