CISA Adds Actively Exploited SharePoint Zero-Day RCE to Known Exploits List
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability in Microsoft SharePoint, tracked as CVE-2026-58644, to its Known Exploited Vulnerabilities catalog. This zero-day is already being actively exploited in attacks, prompting urgent calls for organizations to apply available patches immediately. The addition underscores the high risk of unpatched SharePoint servers.