CISA가 Microsoft SharePoint에 대한 새로운 RCE 제로데이 취약점을 KEV 목록에 추가했습니다.
미국 사이버 보안 및 인프라 보안국(CISA)은 Microsoft SharePoint 서버에서 발생하는 새로운 보안 결함을 알려진 악용 취약점 목록에 추가했습니다. 이 취약점(CVE-2026-58644)은 CVSS 점수 9.8로, 연방 정부 기관은 2026년 7월 19일까지 수정을 적용해야 합니다. 이 취약점은 중요한 탈serialize 문제로, 공격자는 이를 이용해 원격 코드 실행을 실행할 수 있습니다.
CISA adds new RCE zero-day vulnerability for Microsoft SharePoint to its KEV list.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a new security flaw affecting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability, CVE-2026-58644, has a CVSS score of 9.8, and federal agencies are required to apply the fixes by July 19, 2026. This critical deserialization issue allows attackers to execute remote code.