CVE Tools
Back to feed
Exploited in the wild SharePoint Server Subscription Edition rce SharePoint Server 2019 Microsoft web-app

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability affecting Microsoft SharePoint Server to its list of known exploited vulnerabilities. The flaw, tracked as CVE-2026-58644, allows attackers with site owner privileges to execute arbitrary code remotely. Patches were issued on July 14, 2026, but the vulnerability had already been actively exploited before fixes became available. Affected products include SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. CISA urges organizations to apply updates immediately to prevent potential breaches.