High severity8.8CISA KEVNVD Advisory· Published May 22, 2026· Updated Jul 23, 2026
CVE-2026-45659
CVE-2026-45659
Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Affected products
4cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*+ 2 more
- cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*range: <16.0.19725.20280
- cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
- cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659nvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
27- SharePoint Vulnerability Exploited Shortly After PoC ReleaseSecurityWeek · Aug 12, 2026
- Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of AttacksSecurityWeek · Jul 22, 2026
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoCThe Hacker News · Jul 21, 2026
- Microsoft SharePoint Vulnerabilities Actively Exploited for RCE, Web Shells, and IIS Key TheftCyber Security News · Jul 20, 2026
- Breach Roundup: Extortionists Annoyed by Waning RansomwareGovInfoSecurity · Jul 17, 2026
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEVThe Hacker News · Jul 17, 2026
- CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server VulnerabilitiesTenable Blog · Jul 16, 2026
- CISA sounds alarm over trio of exploited SharePoint flawsThe Register Security · Jul 15, 2026
- CISA Urges Immediate Patching of Exploited SharePoint VulnerabilitiesSecurityWeek · Jul 15, 2026
- Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch TuesdayThe Hacker News · Jul 15, 2026
- AI-driven bug hunting fuels record Microsoft Patch TuesdayHelp Net Security · Jul 15, 2026
- CISA warns admins to patch actively exploited SharePoint flawsBleepingComputer · Jul 15, 2026
- Microsoft said exploitation was 'less likely' ... but CISA just added SharePoint RCE to KEV listThe Register Security · Jul 2, 2026
- CISA: Microsoft SharePoint RCE flaw now actively exploitedBleepingComputer · Jul 2, 2026
- CISA Warns of Actively Exploited Microsoft SharePoint VulnerabilitySecurityWeek · Jul 2, 2026
- CISA Warns of Microsoft SharePoint Server Code Execution Vulnerability Exploited in AttacksCyber Security News · Jul 2, 2026
- SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active ExploitationThe Hacker News · Jul 2, 2026
- Microsoft: CVE-2026-45659 Added to CISA KEV Under Active ExploitationVypr Intelligence · Jul 1, 2026
- June 2026 Patch Tuesday forecast: Where are the CVEs?Help Net Security · Jun 5, 2026
- ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and MoreThe Hacker News · Jun 1, 2026
- Week in review: Infostealer dropped via FortiClient EMS flaw, exploited Trend Micro Apex One flawHelp Net Security · May 31, 2026
- Microsoft Issues Out-of-Band SharePoint PatchDark Reading · May 26, 2026
- Microsoft SharePoint Server Vulnerability Enables Remote Code Execution AttacksCyber Security News · May 26, 2026
- Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server VersionsThe Hacker News · May 26, 2026
- High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659)Help Net Security · May 26, 2026
- CISA Urges SharePoint Hardening After New ExploitationsCISA Alerts
- CISA Adds One Known Exploited Vulnerability to CatalogCISA Alerts