High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-45659 | Authenticated Deserialization RCE in Microsoft SharePoint Server (Actively Exploited) CVE-2026-45659 is a deserialization-of-untrusted-data vulnerability (CWE-502) in Microsoft SharePoint Server in which an authorized (authenticated, low-privilege) attacker can submit crafted serialized data over the network, with no user interaction required, to execute code on the server. Successful exploitation carries high impact on confidentiality, integrity, and availability within the SharePoint service context, giving attackers a foothold for follow-on activity, and CISA notes that ransomware use is known. Organizations running on-premises Microsoft SharePoint Server are affected; the source data lists no specific version ranges, and the CPE scope (sharepoint server) points to the on-premises product rather than the Microsoft-managed SharePoint Online service. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-01 after active exploitation, and its EPSS score of 76.1% (100th percentile) indicates a high probability of near-term exploitation. The CVE record lists no public proof-of-concept, though related reporting describes exploitation activity following a public PoC release for a SharePoint authentication bypass. Do: Apply Microsoft's current security updates for SharePoint Server following vendor instructions, prioritizing internet-facing servers, and comply with CISA BOD 26-04, which requires applying mitigations per vendor guidance (including the cited Forensics Triage Requirements) or discontinuing use of the product if mitigations are unavailable. Because in-the-wild exploitation and ransomware use are confirmed, triage exposed servers for compromise: review IIS/SharePoint logs for unexpected authenticated requests, look for webshells or newly modified files in SharePoint web roots, and check for unusual child processes spawned by the SharePoint application pool. Given related reporting on an authentication-bypass PoC, also verify that any related SharePoint authentication-bypass patches are… | 8.8 | 76% | KEV ransomware |
| mass≈100,000 internet-exposed SharePoint Server deployments (order-of-magnitude estimate), with total users across on-premises deployments likely in the millions |
Full article378 words · extracted from helpnetsecurity.com · click to collapse
Microsoft has released patches for a high-severity remote code execution vulnerability (CVE-2026-45659) in SharePoint that may be exploited in low-complexity attacks.

It affects the SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016.
About CVE-2026-45659
CVE-2026-45659 stems from Shareoint deserializing untrusted data, and may be exploited by an authenticated attacker to execute code remotely on a vulnerable SharePoint Server instance – no user interaction required.
“The attack complexity is Low (AC:L) because an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component,” Microsoft explained.
In order to exploit it, though, attackers must first successfully authenticate to the server.
SharePoint: A popular target
SharePoint servers are an attractive target for attackers as they often hold sensitive company data and are usually accessible from the internet.
SharePoint has had several critical, actively exploited vulnerabilities over the years, including remote code execution flaws that required no authentication, minimal (such as those required to exploit CVE-2026-45659), or even high privileges .
Deployments have been targeted by nation-state hackers, ransomware operators, and initial access brokers.
Though Microsoft deems CVE-2026-45659 less likely to be exploited, and there is currently no public details about it or a PoC exploit for it, organizations with on-prem SharePoint servers “should still treat this as a material update,” and implement it sooner rather than later.
The vulnerability has been fixed in:
- SharePoint Server Subscription Edition, build number 16.0.19725.20280
- SharePoint Server 2019, build number 16.0.10417.20128
- SharePoint Enterprise Server 2016, build number 16.0.5552.1002.
UPDATE (May 27, 2026, 03:20 a.m. ET):
Microsoft has updated the advisory to say that CVE-2026-45659 was addressed by updates that were released in May 2026, but the CVE was inadvertently omitted from the May 2026 Security Updates.
“Customers who have already installed the May 2026 updates do not need to take any further action,” the company added.
UPDATE (July 2, 2026, 07:30 a.m. ET):
CISA has added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog, and has set a remediation deadline for July 4, 2026. US federal civilian agencies must also perform forensic triage to detect potential compromise.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/05/26/sharepoint-vulnerability-cve-2026-45659/