top of page

CISA Adds Critical SharePoint RCE Zero-Day CVE-2026-58644 to KEV Catalog Due to Active Exploitation

  • 6 days ago
  • 3 min read

Key Findings


  • CISA added CVE-2026-58644, a critical SharePoint Server remote code execution vulnerability, to its Known Exploited Vulnerabilities catalog on July 16, 2026

  • The vulnerability was actively exploited in the wild before Microsoft released patches on July 14, 2026, making it a zero-day at the time of exploitation

  • Federal Civilian Executive Branch agencies must remediate the flaw by July 19, 2026, under BOD 26-04

  • CISA also added two critical Fortinet FortiSandbox vulnerabilities (CVE-2026-25089 and CVE-2026-39808) to the KEV catalog following confirmed active exploitation

  • The SharePoint flaw affects all supported on-premises versions: Subscription Edition, Server 2019, and Server 2016


Background


CVE-2026-58644 represents a significant shift in vulnerability disclosure timelines. Microsoft initially classified the flaw as "Exploitation More Likely" on July 15, but CISA confirmed active exploitation just one day later. This rapid escalation underscores the severity of the threat and the real-world weaponization that occurred before patches became available.


Technical Details of CVE-2026-58644


The vulnerability scores 9.8 on the CVSS scale and stems from improper deserialization of untrusted data in SharePoint Server. An authenticated attacker with Site Owner privileges can write and inject arbitrary code for remote execution on the server. The attack complexity is low because attackers need minimal prior knowledge of the system and can achieve repeatable success with standardized payloads.


Microsoft confirmed the vulnerability is remotely exploitable over the internet, though the company's advisory clarifies that attackers must have at least Site Owner level authentication. This authentication requirement creates an important distinction when modeling organizational risk.


Affected Versions and Patch Status


The flaw impacts Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Patches were released as part of Microsoft's July 14, 2026 Patch Tuesday cycle. Organizations should note that July's Patch Tuesday ended support for SharePoint Server 2016 and 2019, requiring migration planning alongside immediate patching efforts.


Broader Exploitation Campaign


CISA warned of active exploitation involving multiple SharePoint Server vulnerabilities beyond CVE-2026-58644. Threat actors are leveraging CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 to establish persistence and deploy malware. Attackers employ post-exploitation techniques including stealing Internet Information Services machine keys and using deserialization methods to maintain access after initial compromise.


FortiSandbox Vulnerabilities


On the same day, CISA added two critical Fortinet FortiSandbox flaws to the KEV catalog. CVE-2026-25089 (CVSS 9.1) allows unauthenticated attackers to inject OS commands through crafted HTTP requests. CVE-2026-39808 (CVSS 9.1) presents similar command injection risks. Both flaws carry particular weight because other Fortinet products depend on FortiSandbox verdicts to block threats. An attacker compromising the sandbox can poison security decisions across the entire Fortinet stack.


Threat intelligence firm Defused observed exploitation attempts against both FortiSandbox vulnerabilities in June, though Fortinet had not initially confirmed in-the-wild activity. CISA's KEV listing validates those concerns.


Recommended Hardening Measures


CISA outlined several steps to contain threats from these vulnerabilities. Organizations should apply all latest patches from Microsoft and Fortinet immediately, verifying successful installation and shortening patching cycles where possible. For SharePoint specifically, administrators should enable Antimalware Scan Interface integration for each web application.


Organizations must scan for and remove intrusion artifacts including machine key harvesting tools before rotating IIS machine keys to prevent credential theft. Establishing tailored logging mechanisms can detect exploitation activities early. Where possible, avoid exposing SharePoint Servers directly to the internet, block external access to Central Administration, and restrict farm and database communications to required systems only. Microsoft's security-hardening guidance provides role-specific recommendations for ports, services, and Web.config settings.


Compliance Deadlines


Federal agencies face a July 19, 2026 deadline to remediate all three vulnerabilities under BOD 26-04. This mandate carries additional forensic triage expectations. While commercial organizations lack a mandated timeline, CISA's KEV catalog listing signals an urgent patch-now priority rather than a future consideration. Organizations should treat these entries with the same urgency as federal deadlines given the confirmed active exploitation.


Sources


  • https://thehackernews.com/2026/07/cisa-adds-exploited-sharepoint-rce-zero.html

  • https://securityonline.info/cisa-kev-fortisandbox-sharepoint/

  • https://samithota.com/security-advisories/cve-2026-58644-sharepoint

  • https://www.linkedin.com/posts/netmanageit_cisa-adds-exploited-sharepoint-rce-zero-day-activity-7483774615983640576-eqwu

  • https://x.com/TheHackersNews/status/2078008977636700169

Recent Posts

See All

Comments


  • Youtube

© 2025 by Explain IT Again. Powered and secured by Wix

bottom of page