Wire · regulatory
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 17 July 2026 · Fusion42 review
CISA added CVE-2026-58644, a critical SharePoint Server remote code execution zero-day (CVSS 9.8), to its Known Exploited Vulnerabilities catalogue on 17 July 2026, with a mandatory patch deadline of 19 July for US federal agencies. The vulnerability allows authenticated attackers to execute arbitrary code remotely with low complexity and has been actively exploited in the wild.
This Wire brief sits within Fusion42's coverage of Cybersecurity.
◆ ◆ The Wire takeaway
If you build or sell to US federal agencies, you have 48 hours to patch SharePoint or lose access to that customer base—CISA just made this mandatory, and the exploit is live. That deadline moves every supplier upstream: hosting providers, system integrators, and security vendors all get pulled into the same two-day window.
◆ Coverage
1 source · 17 Jul 2026
◆ Related on Wire
◆ Topics