{"id":1839,"date":"2026-07-17T07:56:56","date_gmt":"2026-07-17T07:56:56","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1839"},"modified":"2026-07-17T07:56:56","modified_gmt":"2026-07-17T07:56:56","slug":"cisa-adds-exploited-sharepoint-rce-zero-day-cve-2026-58644-to-kev","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1839","title":{"rendered":"CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 17, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Enterprise Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgH1X7ZnvKsW37BBvjNfEzT4Imh9ZIRL4_2W1JaNVe_MyO3Q5H1MPsET-SASqznhlfOExRrLj4-6NzhgvGi76w4U5tSmlM-pJLIqO5jF3g9G1DR_FNhuwcatBFb8ARvD4PPMiQvMCFiTlEOlc13nQbQqCn5ZHf1J2ZOqDeG3_pmBiQ92hTfMErJKcjKbNtZ\/s1700-e365\/sharepoint-cisa.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/07\/16\/cisa-adds-three-known-exploited-vulnerabilities-catalog\" target=\"_blank\">added<\/a> a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (<a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\">KEV<\/a>) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026.<\/p>\n<p>The vulnerability in question is <strong>CVE-2026-58644<\/strong> (CVSS score: 9.8), a critical deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute arbitrary code.<\/p>\n<p>\u00abIn a network-based attack, an attacker authenticated as at least a Site Owner, could write arbitrary code to inject and execute code remotely on the SharePoint Server,\u00bb Microsoft <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-58644\" target=\"_blank\">said<\/a> in an advisory released earlier this week.<\/p>\n<p>Redmond noted that the vulnerability is remotely exploitable over the internet, warning that the attack complexity is low for two reasons &#8211;<\/p>\n<ul>\n<li>An attacker does not require significant prior knowledge of the system<\/li>\n<li>An attacker can achieve repeatable success with the payload against the vulnerable component<\/li>\n<\/ul>\n<p>The vulnerability impacts the following versions &#8211;<\/p>\n<ul>\n<li>Microsoft SharePoint Server Subscription Edition<\/li>\n<li>Microsoft SharePoint Server 2019<\/li>\n<li>Microsoft SharePoint Enterprise Server 2016<\/li>\n<\/ul>\n<p>Patches for the flaw have been <a href=\"https:\/\/thehackernews.com\/2026\/07\/researcher-drops-new-windows-zero-day.html\" target=\"_blank\">released as part of the Patch Tuesday updates released on July 14, 2026. Microsoft has since revised its bulletin to clarify that CVE-2026-58644 has been exploited in the wild, meaning the shortcoming was weaponized as a zero-day prior to the fixes becoming available.<\/p>\n<p>The development comes as CISA <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/07\/14\/cisa-urges-sharepoint-hardening-after-new-exploitations\" target=\"_blank\">warned<\/a> of active exploitation of multiple SharePoint Server vulnerabilities, including  CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644, that could enable threat actors to gain unauthorized access to on-premises instances.<\/p>\n<p>\u00abThese vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution (RCE) and post-exploitation activities, such as stealing Internet Information Services (IIS) machine keys and performing deserialization techniques, to gain persistence and deploy malware,\u00bb the federal cybersecurity watchdog noted.<\/p>\n<p>CISA has outlined the following hardening measures to contain the threat &#8211;<\/p>\n<ul>\n<li>Apply the latest patches and security updates from Microsoft, verify they have been installed successfully, and shorten patching cycles when possible.<\/li>\n<li>Verify that Antimalware Scan Interface (<a href=\"https:\/\/learn.microsoft.com\/en-us\/sharepoint\/security-for-sharepoint-server\/configure-amsi-integration\" target=\"_blank\">AMSI<\/a>) integration is enabled for each SharePoint web application.<\/li>\n<li>Scan for and remove intrusion artifacts, including machine key harvesting tools, before rotating IIS machine keys to avoid the theft of the keys.<\/li>\n<li>Establish tailored logging mechanisms to detect and monitor exploitation activities.<\/li>\n<li>Avoid exposing SharePoint Servers directly to the internet unless necessary.<\/li>\n<li>Block external access to SharePoint Central Administration, restrict farm and database communications to required systems, and review Microsoft&#8217;s <a href=\"https:\/\/learn.microsoft.com\/en-us\/sharepoint\/security-for-sharepoint-server\/security-hardening\" target=\"_blank\">SharePoint Server security-hardening guidance<\/a> for role-specific ports, services, and Web.config settings.<\/li>\n<\/ul>\n<p>On Thursday, the agency also added two critical security flaws impacting Fortinet FortiSandbox (CVE-2026-25089 and CVE-2026-39808) to the KEV catalog, following <a href=\"https:\/\/www.crowdsec.net\/vulntracking-report\/cve-2026-39808-fortinet-fortisandbox-command-injection\" target=\"_blank\">reports<\/a> of active exploitation. Federal agencies have until July 19, 2026, to update their instances to the latest supported versions.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jul 17, 2026Vulnerability \/ Enterprise Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1840,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[200,62,2583,128,203,316,751,126],"class_list":["post-1839","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-adds","tag-cisa","tag-cve202658644","tag-exploited","tag-kev","tag-rce","tag-sharepoint","tag-zeroday"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1839","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1839"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1839\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1840"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1839"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1839"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1839"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}