CVE-2026-45659
Published May 22, 2026
Last updated 19 days ago
AI description
CVE-2026-45659 is a remote code execution (RCE) vulnerability found in Microsoft SharePoint Server, stemming from a deserialization of untrusted data issue. This flaw allows an authenticated attacker with low privileges, such as a Site Member, to execute arbitrary code on the server without requiring user interaction. The vulnerability affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Despite Microsoft initially assessing the vulnerability as "less likely to be exploited," the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-45659 to its Known Exploited Vulnerabilities (KEV) catalog in July 2026, confirming active exploitation in the wild. A patch for this vulnerability was included in the May 2026 security updates, though its details were inadvertently omitted from the initial release notes.
- Description
- Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
- Products
- sharepoint_server
CVSS 3.1
- Type
- Secondary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
Data from CISA
- Vulnerability name
- Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
- Exploit added on
- Jul 1, 2026
- Exploit action due
- Jul 4, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- secure@microsoft.com
- CWE-502
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
5
CVE-2026-45659. CVE-2026-45659 added to CISA KEV: Microsoft SharePoint Server
@lyrie_ai
20 Jul 2026
39 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
00:00 UTC: CVE-2026-45659 disclosed. CISA: CVE-2026-45659 added to Known Exploited Vulnerabilities — Microsoft SharePoint Server CVE-2026-45659 added to CISA KEV: Microsoft SharePoint Server
@lyrie_ai
20 Jul 2026
37 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
SharePoint CVEs FAQ: CVE-2026-56164, CVE-2026-32201, CVE-2026-45659 | Tenable® https://t.co/SRRYYVs3Jv
@endi24
19 Jul 2026
2542 Impressions
5 Retweets
23 Likes
18 Bookmarks
0 Replies
0 Quotes
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/denoKmLMkf https://t.co/lvM94DeVpG
@EAlexStark
17 Jul 2026
69 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/Qr0dCd19Nh https://t.co/wD4LUwwYHc
@dansantanna
17 Jul 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Four on-premises SharePoint Server CVEs are actively exploited: CVE-2026-32201 (CVSS 6.5), CVE-2026-45659 (CVSS 8.8), CVE-2026-56164 (CVSS 9.8), and CVE-2026-58644 (CVSS 9.8). #DFIR_Radar https://t.co/ln2QdK28Q8
@DFIR_Radar
17 Jul 2026
190 Impressions
0 Retweets
1 Like
1 Bookmark
2 Replies
0 Quotes
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Exploitation Warnings for SharePoint Server Demand Immediate Action https://t.co/uVEGqZq5Sn #CVE2026 #SharePoint #CyberSecurity
@cyber_newsroom
16 Jul 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
These security flaws (tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) affect all supported self-hosted SharePoint Server versions. https://t.co/q9ukzEgfYf
@jbhall56
15 Jul 2026
60 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: SharePoint Server Active Exploi… "On July 14, 2026, CISA issued an urgent alert regarding active exploitation of…" 🔗 https://t.co/A0C48eSEX9 #CyberSecurity #ThreatIntel #managedsoc #mdr #securitymonito
@SecurityAr58409
15 Jul 2026
59 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA warns SharePoint vulnerabilities CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 are exploited in the wild. Patch and harden servers now. #CISA #SharePoint #Microsoft #CVE #CyberSecurity https://t.co/SN49kOAPnL
@Daily_CyberSec
15 Jul 2026
375 Impressions
1 Retweet
2 Likes
0 Bookmarks
1 Reply
0 Quotes
Adobe ColdFusionのPath Traversal脆弱性 CVE-2026-48282、そしてMicrosoft SharePoint ServerのDeserializationの脆弱性 CVE-2026-45659もKEVの是正期限が過ぎています。これらも任...
@Joe_Biden_ja
11 Jul 2026
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛑 SharePoint CVE-2026-45659 active exploitation puts on-prem servers on u… CISA added SharePoint Server CVE-2026-45659 to KEV after active exploitation. Defenders sho… 🔗 Details → https://t.co/DjxT4dttNT
@lucasverdan
6 Jul 2026
51 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-45659: SharePoint deserialization RCE (CVSS 8.8) on CISA KEV. Only needs Site Member perms. Microsoft rated 'Exploitation Less Likely' — CISA proved otherwise. FCEB patch deadline was July 4. On-prem SharePoint? Patch. Now. #InfoSec #CVE #Cybersecurity
@infrasecserv
5 Jul 2026
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-45659: SharePoint RCE, CVSS 8.8, now on CISA KEV. Patched in May, disclosed a few weeks later, confirmed actively exploited since. A reminder that patch timing and disclosure timing don't always line up, and that gap matters for VM prioritization. #CVE #CyberSecurity
@ssomya395
5 Jul 2026
50 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA warns of actively exploited SharePoint RCE (CVE-2026-45659), demanding immediate patches. This network vulnerability seriously impacts data privacy & integrity in transit. Vigilance is critical! #Cybersecurity #NetworkSecurity #CVE
@YourAnon_irc
4 Jul 2026
42 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
fake poc github: hxxps[://]github[.]com/mistbarbarianspot/CVE-2026-45659-SharePoint-RCE CVE-2026-45659
@UK_Daniel_Card
3 Jul 2026
2417 Impressions
1 Retweet
6 Likes
3 Bookmarks
0 Replies
0 Quotes
CVE-2026-45659 - Edward Snowden's (The SharePoint admin) fave platform has a CVE... it's in CISA KEV! https://t.co/dByWYfNhD5 https://t.co/6Z5w94QTCG
@UK_Daniel_Card
3 Jul 2026
12705 Impressions
19 Retweets
160 Likes
86 Bookmarks
3 Replies
0 Quotes
Legacy exposure keeps paying off for attackers. SharePoint CVE-2026-45659 active exploitation puts on-pre… CISA added SharePoint Server CVE-2026-45659 to KEV after active exploitation. Defenders sho… 🔗 Read → https://t.co/97l4UhUCeq
@fynn_JourX
3 Jul 2026
50 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
For defenders, sharepoint cve-2026-45659 active exploitation puts on-prem serv… should move fast. CISA added SharePoint Server CVE-2026-45659 to KEV after active exploitation. Defenders sho… 🔗 Details → https://t.co/EpEDDraMJk
@SocXAInvaders
3 Jul 2026
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
$MSFT flaw by July 4. CISA added CVE-2026-45659 (CVSS 8.8) to its KEV list. Any authenticated user with basic Site Member rights can run code on-prem. Attacker and method remain unknown.$MSFT flaw by July 4. CISA added CVE-2026-45659 (CVSS 8.8) to its KEV list. Any authenticated
@ShortInfoNews
2 Jul 2026
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
❗ SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation Critical CVE / Exploit: The U.S. Cybersecurity and Infrastructure Security A... https://t.co/zKDRvBs8Qv #CVE #CyberSecurity #InfoSec #Cybersecurity
@MyDooM15
2 Jul 2026
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ CVE-2026-45659: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Server Explotada Activamente Análisis técnico del CVE-2026-45659 en Microsoft SharePoint Server: deserialización de datos no confiables con CVSS 8.8 explotada activamente. Mitigaciones
@CiberPlanetaOrg
1 Jul 2026
44 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft June 2026 Patch Tuesday is live. Exchange CVE-2026-42897 (CVSS 8.1, actively exploited OWA spoofing): permanent patch replaces the EMES temporary mitigation. SharePoint CVE-2026-45659 (CVSS 8.8 RCE) also drops today. Secure Boot legacy UEFI certs expire June 24.
@XavierRiveraX
9 Jun 2026
116 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-45659: Microsoft SharePoint Server RCE flaw patched. The vulnerability is caused by deserialization of untrusted data and may allow authenticated attackers https://t.co/1Wg7XVYZyo #SharePoint #CVE #RCE #CyberSecurity #Vulert
@vulert_official
1 Jun 2026
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ثغرة تنفيذ كود عن بُعد في خادم مشاركة المحتوى المؤسسي يمكن استغلالها دون شروط خاصة، رُقّعت هذا الأسبوع المعرّف : CVE-2026-45659 درجة الخطورة : 8.8 (CVSS) - Important المن
@KasperskyDev
31 May 2026
67 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions. The vulnerability, tracked as CVE-2026-45659, carries a CVSS score of 8.8. It has been assigned an important severity. https://t.co/cDnGNRpGrC https://t.co/AbtzvOk976
@riskigy
30 May 2026
39 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft SharePoint RCE Flaw (CVE-2026-45659, CVSS 8.8) Patched Out-of-Band #cybersecurity #Microsoft #SharePoint #vulnerability #patchnow #enterprisesecurity https://t.co/Nnhx4eN4ET
@JNitterauer
28 May 2026
70 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Guía de remediación urgente: #Vulnerabilidad RCE en #SharePoint (CVE-2026-45659) https://t.co/ZiQr2jUmXG
@newstecnicas
28 May 2026
39 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISO Daily Briefing: Gitea CVE-2026-27771 left 30,000+ self-hosted instances silently leaking private container images — healthcare, aerospace, ISPs affected — for nearly 4 years; Microsoft SharePoint CVE-2026-45659 is critical RCE for enterprise deployments; HiddenLayer's 20
@cloudsa
28 May 2026
164 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ثغرة في خوادم منصة شهيرة لإدارة المحتوى المؤسسي تسمح لمهاجم بأدنى صلاحيات عضو موقع بتنفيذ كود عن بُعد عبر إلغاء تسلسل بيانات غير موثوقة. المنتج : Microsoft Share
@KasperskyDev
28 May 2026
184 Impressions
1 Retweet
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Top 5 Trending CVEs: 1 - CVE-1999-0997 2 - CVE-2026-45659 3 - CVE-2026-23652 4 - CVE-2026-45585 5 - CVE-2024-52577 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
28 May 2026
98 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Critical #SharePointServer vulnerability (CVE-2026-45659) allows remote code execution. Apply patches immediately to secure your systems. #SharePoint #CVE #RCE #Patch #Security #Cybersecurity #Infosec #Microsoft #Vulnerability #Exploit #Servers #Update #Mitigation #Threat #Risk h
@dailytechonx
27 May 2026
70 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-45659: Microsoft SharePoint Unauthenticated RCE — Detection and Remedi… "Unauthenticated RCE in Microsoft SharePoint (CVE-2026-45659). Patch immediately to prevent…" 🔗 https://t.co/lrwpD8J3LG #CyberSecurity #ThreatIntel #cve #zeroday
@SecurityAr58409
27 May 2026
49 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2026-45659 2 - CVE-2026-5426 3 - CVE-2026-48172 4 - CVE-2024-12802 5 - CVE-2026-8945 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
27 May 2026
99 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
🩹マイクロソフト、SharePointの深刻なRCE脆弱性にパッチ(CVE-2026-45659) ⚠️ハッカーがKnowledgeDeliverのゼロデイを悪用し、Webシェルとバックドアを展開(CVE-2026-5426) 〜サイバーアラート5月27日〜 https://t.co/X6yz
@MachinaRecord
27 May 2026
167 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨 HIGH SEVERITY: CVE-2026-45659 (CVSS 8.8) Deserialization flaw in Microsoft SharePoint allows authenticated attackers to execute remote code over network. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR https://t.co/62V8Mrbba0
@DFIR_Lab
27 May 2026
53 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
MicrosoftがSharePointのリモートコード実行脆弱性CVE-2026-45659をサーバーバージョン全体で修正 Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions #HackerNews (May 26) https://t.co/WGO90LPJFj
@foxbook
27 May 2026
213 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft patches CVE-2026-45659 in SharePoint, a high-severity RCE flaw tied to untrusted deserialization. Authenticated users with minimal rights could exploit it. #MicrosoftSharePoint #CVE-2026-45659 #MEOW https://t.co/b1k7X8wMUq
@TweetThreatNews
26 May 2026
137 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-45659: Microsoft SharePoint Unauthenticated RCE — Detection and Remedi… "Critical unauthenticated RCE (CVE-2026-45659) in Microsoft SharePoint requires immediate…" 🔗 https://t.co/q0QK0mu8iM #CyberSecurity #ThreatIntel #cve #zeroday #patch
@SecurityAr58409
26 May 2026
67 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔬 Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions Vulnerability / Critical CVE: Microsoft has rolled out updates to fix a remote cod... https://t.co/Ef8gRZabgF #CVE #AppSec #CyberSecurity #Privacy
@MyDooM15
26 May 2026
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft patches SharePoint RCE flaw CVE-2026-45659 (CVSS 8.8) Authenticated attacker (Site Member) bisa execute code remotely. Update sekarang! Artikel: https://t.co/IJvIqaHFju Follow @csalab.id #SharePoint #RCE #CVE #CyberSecurity https://t.co/pXMyHSYHU0
@csalab_id
26 May 2026
23 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions https://t.co/jdDr9GpljR
@VivekIntel
26 May 2026
126 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
NEW THREAT INTEL: SharePoint Authd RCE (CVE-2026-45659) - .NET deserialization, code exec as w3wp. 9 detections. https://t.co/6P1LmqMG34 #ThreatIntel #SharePoint #CVE https://t.co/gPSsCWq5qM
@threadlinqs
26 May 2026
73 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659): Microsoft has released patches for a high-severity remote code execution vulnerability (CVE-2026-45659) in SharePoint that may be exploited in low-complexity attacks. It affects the… https://t.co/6ZVh4JKjCR
@shah_sheikh
26 May 2026
66 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Urgent SharePoint Patch: Fix Remote Code Execution Flaw CVE-2026-45659 https://t.co/JWRi3E4hZN #Cybertrending #Cybernewsdaily #Cybersecurity
@unknownmatter19
24 May 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Urgent SharePoint Patch: Fix Remote Code Execution Flaw CVE-2026-45659 https://t.co/C3IoJNGEjS #Cybertrending #Cybernewsdaily #Cybersecurity
@CyberInsights1
24 May 2026
3 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*",
"matchCriteriaId": "E9919927-DE08-4AE4-B9F6-2A83117EE14A",
"versionEndExcluding": "16.0.19725.20280",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "F815EF1D-7B60-47BE-9AC2-2548F99F10E4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*",
"matchCriteriaId": "6122D014-5BF1-4AF4-8B4D-80205ED7785E",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]