# CISA Adds Actively Exploited SharePoint Zero-Day RCE to Known Exploits List

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability in Microsoft SharePoint, tracked as CVE-2026-58644, to its Known Exploited Vulnerabilities catalog. This zero-day is already being actively exploited in attacks, prompting urgent calls for organizations to apply available patches immediately. The addition underscores the high risk of unpatched SharePoint servers.

**Importance:** 4/5

## Sources

### Security
- [The Hacker News](https://thehackernews.com/2026/07/cisa-adds-exploited-sharepoint-rce-zero.html) — Fri, 17 Jul 2026 12:12:23 +0530