CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
2026-07-17T07:24:14Z•112bf342acec69c8d91332c3d5f3f42ad234c6dc3ee4ce9dbf989f55f63e8b79
AsyncAPICISAClickLockFirefoxIoT vulnerabilityKEVMicrosoftOkoBotPatch TuesdayPhantomEnigmaRCESAPSSRFSharePointSonicWallTELEPUZZoomagent-data-injectionmalwaren8nnpm compromisesupply-chainzero-day
What happened
A broad set of high‑risk security developments: CISA added a newly patched Microsoft SharePoint remote code execution zero‑day (CVE‑2026‑58644, CVSS 9.8) to its Known Exploited Vulnerabilities (KEV), mandating FCEB agencies remediate by July 19, 2026. Multiple other critical and actively exploited flaws and advisories were reported — SonicWall SMA 1000 zero‑days (including CVE‑2026‑15409, SSRF, CVSS 10.0), Zoom Workplace critical account‑takeover bug (CVE‑2026‑53412, CVSS 9.8), Firefox critical bugs with public exploit code (CVE‑2026‑15718, CVE‑2026‑15719), and a critical SAP NetWeaver ABAP Oo
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 112bf342acec69c8d91332c3d5f3f42ad234c6dc3ee4ce9dbf989f55f63e8b79
- Enrichment time
- 2026-07-17T07:24:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.