The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Microsoft SharePoint Server vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agency patches by July 19, 2026.
Key Points
- The vulnerability, CVE-2026-58644, carries a critical CVSS score of 9.8 and allows unauthorized remote code execution.
- Affected software includes Microsoft SharePoint Server Subscription Edition, 2019, and 2016.
- Microsoft confirmed the flaw was exploited as a zero-day before patches were released on July 14, 2026.
- CISA also added two critical Fortinet FortiSandbox vulnerabilities, CVE-2026-25089 and CVE-2026-39808, to the mandatory remediation list.
- Recommended hardening measures include enabling Antimalware Scan Interface integration and restricting direct internet exposure for SharePoint servers.