CISA has added Microsoft SharePoint Server vulnerability CVE-2026-58644 to its Known Exploited Vulnerabilities catalog, highlighting the flaw as an active security concern. The issue is described as a remote code execution bug that was exploited before Microsoft released a patch.
According to the available details, the vulnerability affects all supported on-premises versions of SharePoint Server. Because the bug can enable remote code execution, successful attacks could give threat actors a powerful path into exposed enterprise environments.
The KEV listing is significant because it signals that the weakness is not just theoretical. CISA uses the catalog to track vulnerabilities that have been observed in real-world attacks, and the addition of CVE-2026-58644 raises the urgency for organizations running SharePoint on-premises.
For IT and security teams, the development puts the focus on identifying affected SharePoint deployments and applying Microsoft's fix as quickly as possible. The case also underscores the continuing risk around internet-facing collaboration platforms when newly disclosed flaws are already being exploited in the wild.