// Alert

Microsoft Azure threat report

CISA added CVE-2026-58644, a critical deserialization remote-code-execution vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog on July 16, 2026. The flaw affects all supported on-premises versions (Subscription Edition, 2019, and 2016) and allows authenticated attackers to execute arbitrary code with low attack complexity. The vulnerability was actively exploited in the wild before Microsoft patched it on July 14, 2026. CISA mandated federal agencies patch by July 19, 2026.

// Get alerts for Microsoft Azure