A critical vulnerability in Microsoft SharePoint is being actively exploited, according to a warning from the US Cybersecurity and Infrastructure Security Agency (CISA). The vulnerability is identified as CVE-2026-58644, with a high CVSS score of 9.8, indicating its severe impact. This flaw, which was addressed in Microsoft’s July 2026 Patch Tuesday updates, is due to a deserialization issue involving untrusted data. Microsoft explains that this vulnerability allows an attacker, authenticated at least as a Site Owner, to write and execute arbitrary code remotely on the SharePoint server.

Following the initial advisory, Microsoft updated its guidance to indicate that exploitation of this vulnerability had been detected. In response, CISA has added CVE-2026-58644 to its Known Exploited Vulnerabilities catalog, urging federal agencies to apply the necessary patches within three days in accordance with Binding Operational Directive 26-04. This directive emphasizes rapid response to vulnerabilities that are being actively exploited.

Alongside this SharePoint vulnerability, CISA also identified two additional critical flaws in Fortinet FortiSandbox, tracked as CVE-2026-25089 and CVE-2026-39808. These vulnerabilities, patched earlier in the year, also enable attackers to execute arbitrary commands on compromised systems. The prompt action by CISA highlights the urgency required in addressing these security flaws to prevent potential breaches.