Dossier
Microsoft SharePoint Server
Coverage of Microsoft SharePoint Server in the Nexus archive.
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
CISA added a critical SharePoint Server vulnerability (CVE-2026-58644) with a CVSS score of 9.8 to its KEV catalog, requiring FCEB agencies to patch by July 19, 2026. The flaw is a deserialization issue exploitable for remote code execution.
- SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
CISA added a high-severity remote code execution vulnerability (CVE-2026-45659) in Microsoft SharePoint Server to its Known Exploited Vulnerabilities catalog due to active exploitation. The flaw, rated with a CVSS score of 8.8, stems from deserialization of untrusted data.