VYPR
Vypr IntelligenceAI-generatedJul 16, 2026· 1 CVE

Microsoft SharePoint RCE Zero-Day Added to CISA KEV Under Active Exploitation

A critical remote code execution vulnerability in Microsoft SharePoint, CVE-2026-58644, has been confirmed under active exploitation and added to CISA's Known Exploited Vulnerabilities catalog.

Key findings

  • CVE-2026-58644, a Microsoft SharePoint RCE flaw, is now in CISA's KEV catalog.
  • The vulnerability is confirmed to be under active exploitation in the wild.
  • Remote Code Execution (RCE) flaws are critical and can lead to full system compromise.
  • Immediate patching of affected Microsoft SharePoint systems is imperative.
  • CISA's KEV listing mandates urgent remediation for federal agencies.

CISA has added CVE-2026-58644, a remote code execution (RCE) vulnerability affecting Microsoft SharePoint, to its Known Exploited Vulnerabilities (KEV) catalog. This addition on July 16, 2026, signals that the flaw is being actively exploited in real-world attacks, elevating its urgency for immediate remediation by federal agencies and critical infrastructure organizations.

The vulnerability, identified as CVE-2026-58644, allows for remote code execution within Microsoft SharePoint environments. Such flaws are highly prized by attackers as they can lead to full system compromise, data exfiltration, or the deployment of further malicious payloads, often without requiring user interaction.

The inclusion of any vulnerability in the KEV catalog serves as a definitive warning that adversaries are leveraging the flaw. For organizations utilizing Microsoft SharePoint, the presence of an actively exploited RCE vulnerability poses a significant and immediate security risk that cannot be ignored.

Defenders are strongly advised to prioritize patching for CVE-2026-58644 without delay. CISA's Binding Operational Directive (BOD) 22-01 mandates that federal civilian executive branch agencies remediate KEV vulnerabilities by specific due dates, underscoring the critical need for prompt action across all affected sectors. Organizations should consult Microsoft's official security advisories for patches and apply them immediately to mitigate the risk of compromise.

AI-written article. Grounded in 1 CVE record listed below.