CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

A Critical SharePoint Vulnerability Has Been Added to CISA’s KEV List, Posing Significant Risks for Enterprises Worldwide

The US Cybersecurity and Infrastructure Security Agency (CISA) has taken swift action by adding a zero-day vulnerability in Microsoft SharePoint, known as CVE-2026-58644, to its Known Exploited Vulnerabilities (KEV) list. This move is a timely warning to organizations that rely on the popular collaboration platform, signaling that exploitation of this flaw is already underway.

The critical Remote Code Execution (RCE) bug affects multiple versions of SharePoint, with attackers exploiting it to execute arbitrary code on affected systems. This vulnerability was first identified by AI-driven security tools, which have become increasingly effective at uncovering hidden threats. While AI has proven to be a valuable asset in cybersecurity, its emergence as a discovery tool also underscores the importance of proactive defense strategies.

Microsoft SharePoint is widely used across industries for collaboration and document management, making it a prime target for attackers seeking to gain unauthorized access to sensitive information. The KEV list, maintained by CISA, catalogues known vulnerabilities that have been exploited in the wild, serving as a crucial resource for organizations to prioritize their patching efforts. By adding CVE-2026-58644 to this list, CISA is alerting administrators to the fact that exploitation of this vulnerability has already begun.

Organizations reliant on SharePoint must take immediate action to address this critical vulnerability. This involves implementing timely patches and ensuring all systems are up-to-date with the latest security updates. Moreover, IT teams should also review their threat detection and response strategies to ensure they can effectively identify and contain potential exploits.

The inclusion of CVE-2026-58644 on the KEV list is a stark reminder that software vulnerabilities can be exploited by attackers in a matter of hours after discovery. This highlights the importance of continuous monitoring, rigorous patch management, and proactive threat hunting practices within organizations. As AI-driven security tools become increasingly prevalent, they will likely uncover more hidden threats, underscoring the need for robust cybersecurity posture.

To safeguard against such vulnerabilities, it is essential that organizations prioritize regular security audits, implement robust vulnerability management processes, and foster a culture of transparency in their incident response strategies. This proactive approach will enable them to stay ahead of emerging threats and ensure the integrity of their systems, even as AI-driven security tools continue to reveal new and sophisticated risks.


Source: The Hacker News — 2026-07-17