Critical Remote Code Execution in Microsoft SharePoint Server (CVE‑2026‑58644) Added to CISA KEV
What It Is — A critical deserialization flaw in Microsoft SharePoint Server (CVE‑2026‑58644) allows unauthenticated attackers to execute arbitrary code on vulnerable on‑premises servers. Microsoft released a patch in early July 2026; CISA has placed the vulnerability in its Known Exploited Vulnerabilities (KEV) catalog, mandating remediation for Federal Civilian Executive Branch agencies by 19 July 2026.
Exploitability — Actively exploited in the wild; proof‑of‑concept code has been observed. CVSS v3.1 base score 9.8 (Critical).
Affected Products — Microsoft SharePoint Server (on‑premises) versions prior to the July 2026 security update.
Why It Matters for Compliance & Audit Readiness
- Control Mapping – The flaw maps to SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management); evidence of timely patching is a core audit artifact.
- Continuous Evidence – Automated remediation tracking feeds a defensible audit trail, satisfying both internal risk programs and external auditors.
- Enterprise Buyer Expectations – Prospective customers increasingly demand proof of rapid vulnerability remediation as part of SOC 2 readiness assessments.
Recommended Actions
- Deploy Microsoft’s July 2026 security update to all SharePoint Server instances immediately.
- Update your asset inventory and vulnerability management tools to reflect the patched state.
- Capture patch‑deployment logs and map the remediation to SOC 2 CC6.1/CC7.1 controls for audit evidence.
Source: The Hacker News – CISA Adds Exploited SharePoint RCE Zero‑Day CVE‑2026‑58644 to KEV