CISA warns of critical vulnerability in Microsoft SharePoint
CISA has added vulnerability CVE-2026-58644 to its list of exploited threats following the detection of critical remote code execution risks.

Critical Alert: Security breach in SharePoint under scrutiny
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning after adding vulnerability CVE-2026-58644 to its Known Exploited Vulnerabilities (KEV) catalog. This flaw, which directly affects Microsoft SharePoint Server, has been assigned a CVSS score of 9.8, placing it at the highest level of criticality due to its potential to allow remote code execution (RCE).
What does this vulnerability mean for organizations?
The issue stems from a deserialization flaw that, if exploited by an attacker, allows for full control over the affected server. Since SharePoint is a central tool in the corporate infrastructure of numerous agencies and companies, the ability to execute commands remotely represents a high-risk hack.
Federal Civilian Executive Branch (FCEB) agencies have a deadline of July 19, 2026, to apply the relevant security patches. Inaction in the face of such threats not only exposes sensitive data but also opens the door to larger-scale incidents, such as the deployment of ransomware to hijack critical information.
"Inclusion in the KEV list is a clear indicator that threat actors are already actively using this exploit in the wild."
The importance of cyber hygiene
This incident underscores the constant need to keep systems updated, a task that is often outpaced by the creativity of cybercriminals. While server vulnerabilities are a classic vector, attackers are also diversifying their methods. For example, we have seen how other malicious actors use social engineering techniques, such as Russian hackers using fake Zoom and WebEx apps to spread malware, to infiltrate corporate networks.
Security recommendations
To mitigate the risks associated with this and other breaches, it is recommended to follow these guidelines:
- Prioritize patching: Apply official Microsoft updates immediately, especially on servers exposed to the internet.
- Network monitoring: Watch for unusual behavior in SharePoint logs that might suggest deserialization exploitation attempts.
- Segmentation: Isolate critical servers from end-user networks to limit lateral movement in the event of an intrusion.
Cybersecurity is a constant arms race. Staying informed about the KEV catalog is essential for any organization seeking to shield its assets against the growing sophistication of modern attacks.
Sources:
Related articles
7 de septiembre de 2026
Cybersecurity: New ScreenConnect vulnerability facilitates attacks
Researchers have detected a four-stage infection chain that uses ScreenConnect to compromise systems through malicious scripts.
30 de agosto de 2026
Breach at Manchester Airports Group: The hack exposing 86 GB of data
The group FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group, revealing sensitive passenger and booking information.
23 de agosto de 2026
Hackers infect Android car systems: the new vulnerability
A supply chain attack is turning Android-based automotive multimedia systems into part of a botnet, putting driver security at risk.
16 de agosto de 2026
AmnesiaStealer: The new hack compromising macOS security
We analyze AmnesiaStealer, a macOS malware that enables remote browser control and puts user privacy at risk.
Loading comments...