
Software
the other SharePoint bug: a 9.8 that runs code with no login, already exploited and on CISA's list
Everyone focused on the SharePoint privilege-escalation zero-day. CVE-2026-58644 is worse: an unauthenticated deserialization flaw that runs code on the server, actively exploited, with a CISA deadline that's already passed.
Priya Nair · 2d ago · 9 min