← Back

Wire · regulatory

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

Published

17 July 2026

Topic

regulatory

Sectors

Cybersecurity

Geography

United States

Source

Read at thehackernews.com

Verified

Fusion42 · 17 July 2026 · Fusion42 review

CISA added CVE-2026-58644, a critical SharePoint Server remote code execution zero-day (CVSS 9.8), to its Known Exploited Vulnerabilities catalogue on 17 July 2026, with a mandatory patch deadline of 19 July for US federal agencies. The vulnerability allows authenticated attackers to execute arbitrary code remotely with low complexity and has been actively exploited in the wild.

This Wire brief sits within Fusion42's coverage of Cybersecurity.

◆ The Wire takeaway

If you build or sell to US federal agencies, you have 48 hours to patch SharePoint or lose access to that customer base—CISA just made this mandatory, and the exploit is live. That deadline moves every supplier upstream: hosting providers, system integrators, and security vendors all get pulled into the same two-day window.

Coverage

1 source · 17 Jul 2026

Related on Wire

Topics

Cybersecuritysharepoint-rcezero-dayfederal-mandatepatch-deadlinecisa-kev