Microsoft SharePoint RCE zero-day (CVE-2026-58644): exploited in the wild - patch every farm server now
Microsoft disclosed a critical unauthenticated-looking RCE in on-premises SharePoint Server on 14 July 2026 - a deserialization flaw exploited in the wild before patches shipped, now on CISA's KEV list with a 19 July remediation deadline. Here's the briefing, the compromise-hunt, and the action list.
