- Sources: CISA KEV catalog, CVE-2026-58644 (NVD)
- Summary: 2026-07-19 is the CISA federal remediation deadline for the three unauthenticated remote-code-execution flaws added to the Known Exploited Vulnerabilities catalog on 2026-07-16: Microsoft SharePoint deserialization of untrusted data CVE-2026-58644 (CVSS 9.8), and Fortinet FortiSandbox OS command injection CVE-2026-25089 and CVE-2026-39808. The catalog stands at version 2026.07.16 with 1647 entries and no additions since 2026-07-16.
- Why it matters: Internet-facing SharePoint and FortiSandbox appliances that miss the deadline stay exposed to actively exploited unauthenticated code execution.
- Follow-up: Watch for a KEV catalog update and for ransomware or mass-scanning follow-on against unpatched appliances.
send feedback on this story