AI-Generated · deepseek/deepseek-v4-pro via openrouter/openrouter/auto-beta; researched by moonshotai/kimi-k2-0905

CISA Adds Exploited SharePoint RCE to KEV as Three More Flaws Come Under Active Attack

CISA added a critical SharePoint deserialization RCE to its Known Exploited Vulnerabilities catalog just two days after confirming active exploitation of three others, while SharePoint 2016 and 2019 reached end-of-life on the same day the initial trio was disclosed.

CISA Adds Exploited SharePoint RCE to KEV as Three More Flaws Come Under Active Attack
Photo: Fabushnik228, CC BY-SA 4.0

On July 16, 2026, CISA added CVE-2026-58644 to its Known Exploited Vulnerabilities catalog, requiring Federal Civilian Executive Branch agencies to apply fixes by July 19. The vulnerability carries a CVSS score of 9.8 and is caused by a deserialization flaw that allows remote code execution by authenticated attackers with Site Owner permissions.

That KEV entry arrived two days after CISA issued a warning urging all organizations running on-premises SharePoint to harden defenses, confirming active exploitation of three other vulnerabilities: CVE-2026-32201 (spoofing), CVE-2026-45659 (remote code execution), and CVE-2026-56164 (privilege escalation). Attackers have been observed stealing IIS machine keys, weaponizing deserialization techniques, and deploying malware against unpatched servers.

On the same day CISA added CVE-2026-58644 to the KEV catalog, Microsoft updated its advisory to confirm that the vulnerability had been exploited in the wild. All five vulnerabilities affect SharePoint Server Subscription Edition, 2019, and 2016, so the exploitation surface spans the entire on-premises product line.

The Canadian Centre for Cyber Security’s alert AL26-017, also published on July 15, highlighted an additional pressure point: SharePoint Server 2016 and 2019 reached end-of-life on July 14, 2026 — the very day the trio’s exploitation was confirmed. The same alert flagged CVE-2026-55040 alongside CVE-2026-56164 and CVE-2026-58644 as vulnerabilities Microsoft is tracking, meaning organizations still running the newly unsupported editions are managing actively exploited flaws without the safety net of ongoing vendor patches.

By the evening of July 16, five SharePoint vulnerabilities had been confirmed under active exploitation, and federal agencies were left with a three-day patch window for the most critical among them. For any organisation running on-premises SharePoint — supported or not — the timeline makes clear that these are not speculative threats waiting for proof-of-concept code. Exploitation is already underway, and the vulnerability catalogues driving patch priorities are being updated in real time to match what attackers are actually using.

Sources