Critical SharePoint RCE Zero-Day CVE-2026-58644 Explained: CISA Urges Immediate Patching (2026)

CISA's KEV Catalog Expands: Urgent Action Required for SharePoint and Fortinet Vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert, adding two newly patched security flaws to its Known Exploited Vulnerabilities (KEV) catalog. These vulnerabilities, impacting Microsoft SharePoint Server and Fortinet FortiSandbox, demand immediate attention from Federal Civilian Executive Branch (FCEB) agencies.

SharePoint Server Zero-Day Exploit

The most pressing concern is CVE-2026-58644, a critical deserialization of untrusted data vulnerability in Microsoft SharePoint Server. This flaw, with a CVSS score of 9.8, allows unauthorized attackers to execute arbitrary code remotely. Microsoft's advisory highlights the ease of exploitation, emphasizing the low attack complexity due to the attacker's lack of prior knowledge and the repeatability of the payload.

This vulnerability affects Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, and Microsoft SharePoint Enterprise Server 2016. It was patched as part of the July 14, 2026, Patch Tuesday updates, but it's now known to have been weaponized as a zero-day exploit before the fixes were available.

CISA's warning about active exploitation of multiple SharePoint vulnerabilities, including CVE-2026-58644, underscores the urgency. These vulnerabilities enable threat actors to gain unauthorized access, execute remote code, and perform post-exploitation activities like stealing IIS machine keys and deploying malware.

To mitigate the threat, CISA recommends several hardening measures:

  • Apply and verify Microsoft's latest patches and security updates, considering shorter patching cycles.
  • Enable Antimalware Scan Interface (AMSI) integration for SharePoint web applications.
  • Scan and remove intrusion artifacts, including machine key harvesting tools, before rotating IIS machine keys.
  • Implement tailored logging mechanisms for detection and monitoring of exploitation activities.
  • Restrict direct internet exposure of SharePoint Servers and block external access to Central Administration.

Fortinet FortiSandbox Vulnerabilities

CISA also added two critical security flaws in Fortinet FortiSandbox (CVE-2026-25089 and CVE-2026-39808) to the KEV catalog, following reports of active exploitation. Federal agencies have until July 19, 2026, to update their FortiSandbox instances to the latest supported versions.

Personal Reflection

These KEV additions highlight the ever-evolving landscape of cybersecurity threats. The rapid identification and patching of vulnerabilities, followed by their exploitation, demonstrate the need for proactive security measures. Organizations must stay vigilant, adapt quickly, and prioritize patching to safeguard their systems from potential threats.

As an expert, I find it concerning that these vulnerabilities can be weaponized as zero-days, emphasizing the importance of timely patching and security awareness. The KEV catalog serves as a crucial resource for agencies to prioritize their security efforts, but it also underscores the ongoing challenge of staying ahead of emerging threats.

Critical SharePoint RCE Zero-Day CVE-2026-58644 Explained: CISA Urges Immediate Patching (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Aron Pacocha

Last Updated:

Views: 6728

Rating: 4.8 / 5 (48 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Aron Pacocha

Birthday: 1999-08-12

Address: 3808 Moen Corner, Gorczanyport, FL 67364-2074

Phone: +393457723392

Job: Retail Consultant

Hobby: Jewelry making, Cooking, Gaming, Reading, Juggling, Cabaret, Origami

Introduction: My name is Aron Pacocha, I am a happy, tasty, innocent, proud, talented, courageous, magnificent person who loves writing and wants to share my knowledge and understanding with you.