CVE-2026-45659

Published May 22, 2026

Last updated 12 days ago

Exploit knownCVSS high 8.8
Microsoft Office SharePoint

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-45659 is a remote code execution (RCE) vulnerability found in Microsoft SharePoint Server, stemming from a deserialization of untrusted data issue. This flaw allows an authenticated attacker with low privileges, such as a Site Member, to execute arbitrary code on the server without requiring user interaction. The vulnerability affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Despite Microsoft initially assessing the vulnerability as "less likely to be exploited," the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-45659 to its Known Exploited Vulnerabilities (KEV) catalog in July 2026, confirming active exploitation in the wild. A patch for this vulnerability was included in the May 2026 security updates, though its details were inadvertently omitted from the initial release notes.

Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Source
secure@microsoft.com
NVD status
Analyzed
Products
sharepoint_server

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Exploit added on
Jul 1, 2026
Exploit action due
Jul 4, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

secure@microsoft.com
CWE-502

Social media

Hype score
Not currently trending
  1. Adobe ColdFusionのPath Traversal脆弱性 CVE-2026-48282、そしてMicrosoft SharePoint ServerのDeserializationの脆弱性 CVE-2026-45659もKEVの是正期限が過ぎています。これらも任...

    @Joe_Biden_ja

    11 Jul 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🛑 SharePoint CVE-2026-45659 active exploitation puts on-prem servers on u… CISA added SharePoint Server CVE-2026-45659 to KEV after active exploitation. Defenders sho… 🔗 Details → https://t.co/DjxT4dttNT

    @lucasverdan

    6 Jul 2026

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2026-45659: SharePoint deserialization RCE (CVSS 8.8) on CISA KEV. Only needs Site Member perms. Microsoft rated 'Exploitation Less Likely' — CISA proved otherwise. FCEB patch deadline was July 4. On-prem SharePoint? Patch. Now. #InfoSec #CVE #Cybersecurity

    @infrasecserv

    5 Jul 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2026-45659: SharePoint RCE, CVSS 8.8, now on CISA KEV. Patched in May, disclosed a few weeks later, confirmed actively exploited since. A reminder that patch timing and disclosure timing don't always line up, and that gap matters for VM prioritization. #CVE #CyberSecurity

    @ssomya395

    5 Jul 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CISA warns of actively exploited SharePoint RCE (CVE-2026-45659), demanding immediate patches. This network vulnerability seriously impacts data privacy & integrity in transit. Vigilance is critical! #Cybersecurity #NetworkSecurity #CVE

    @YourAnon_irc

    4 Jul 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. fake poc github: hxxps[://]github[.]com/mistbarbarianspot/CVE-2026-45659-SharePoint-RCE CVE-2026-45659

    @UK_Daniel_Card

    3 Jul 2026

    2417 Impressions

    1 Retweet

    6 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2026-45659 - Edward Snowden's (The SharePoint admin) fave platform has a CVE... it's in CISA KEV! https://t.co/dByWYfNhD5 https://t.co/6Z5w94QTCG

    @UK_Daniel_Card

    3 Jul 2026

    12705 Impressions

    19 Retweets

    160 Likes

    86 Bookmarks

    3 Replies

    0 Quotes

  8. Legacy exposure keeps paying off for attackers. SharePoint CVE-2026-45659 active exploitation puts on-pre… CISA added SharePoint Server CVE-2026-45659 to KEV after active exploitation. Defenders sho… 🔗 Read → https://t.co/97l4UhUCeq

    @fynn_JourX

    3 Jul 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. For defenders, sharepoint cve-2026-45659 active exploitation puts on-prem serv… should move fast. CISA added SharePoint Server CVE-2026-45659 to KEV after active exploitation. Defenders sho… 🔗 Details → https://t.co/EpEDDraMJk

    @SocXAInvaders

    3 Jul 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. $MSFT flaw by July 4. CISA added CVE-2026-45659 (CVSS 8.8) to its KEV list. Any authenticated user with basic Site Member rights can run code on-prem. Attacker and method remain unknown.$MSFT flaw by July 4. CISA added CVE-2026-45659 (CVSS 8.8) to its KEV list. Any authenticated

    @ShortInfoNews

    2 Jul 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  11. ❗ SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation Critical CVE / Exploit: The U.S. Cybersecurity and Infrastructure Security A... https://t.co/zKDRvBs8Qv #CVE #CyberSecurity #InfoSec #Cybersecurity

    @MyDooM15

    2 Jul 2026

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🛡️ CVE-2026-45659: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Server Explotada Activamente Análisis técnico del CVE-2026-45659 en Microsoft SharePoint Server: deserialización de datos no confiables con CVSS 8.8 explotada activamente. Mitigaciones

    @CiberPlanetaOrg

    1 Jul 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Microsoft June 2026 Patch Tuesday is live. Exchange CVE-2026-42897 (CVSS 8.1, actively exploited OWA spoofing): permanent patch replaces the EMES temporary mitigation. SharePoint CVE-2026-45659 (CVSS 8.8 RCE) also drops today. Secure Boot legacy UEFI certs expire June 24.

    @XavierRiveraX

    9 Jun 2026

    116 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. 🚨 CVE-2026-45659: Microsoft SharePoint Server RCE flaw patched. The vulnerability is caused by deserialization of untrusted data and may allow authenticated attackers https://t.co/1Wg7XVYZyo #SharePoint #CVE #RCE #CyberSecurity #Vulert

    @vulert_official

    1 Jun 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. ثغرة تنفيذ كود عن بُعد في خادم مشاركة المحتوى المؤسسي يمكن استغلالها دون شروط خاصة، رُقّعت هذا الأسبوع المعرّف : CVE-2026-45659 درجة الخطورة : 8.8 (CVSS) - Important المن

    @KasperskyDev

    31 May 2026

    67 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions. The vulnerability, tracked as CVE-2026-45659, carries a CVSS score of 8.8. It has been assigned an important severity. https://t.co/cDnGNRpGrC https://t.co/AbtzvOk976

    @riskigy

    30 May 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Microsoft SharePoint RCE Flaw (CVE-2026-45659, CVSS 8.8) Patched Out-of-Band #cybersecurity #Microsoft #SharePoint #vulnerability #patchnow #enterprisesecurity https://t.co/Nnhx4eN4ET

    @JNitterauer

    28 May 2026

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 🚨 Guía de remediación urgente: #Vulnerabilidad RCE en #SharePoint (CVE-2026-45659) https://t.co/ZiQr2jUmXG

    @newstecnicas

    28 May 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. CISO Daily Briefing: Gitea CVE-2026-27771 left 30,000+ self-hosted instances silently leaking private container images — healthcare, aerospace, ISPs affected — for nearly 4 years; Microsoft SharePoint CVE-2026-45659 is critical RCE for enterprise deployments; HiddenLayer's 20

    @cloudsa

    28 May 2026

    164 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. ثغرة في خوادم منصة شهيرة لإدارة المحتوى المؤسسي تسمح لمهاجم بأدنى صلاحيات عضو موقع بتنفيذ كود عن بُعد عبر إلغاء تسلسل بيانات غير موثوقة. المنتج : Microsoft Share

    @KasperskyDev

    28 May 2026

    184 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  21. Top 5 Trending CVEs: 1 - CVE-1999-0997 2 - CVE-2026-45659 3 - CVE-2026-23652 4 - CVE-2026-45585 5 - CVE-2024-52577 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    28 May 2026

    98 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  22. Critical #SharePointServer vulnerability (CVE-2026-45659) allows remote code execution. Apply patches immediately to secure your systems. #SharePoint #CVE #RCE #Patch #Security #Cybersecurity #Infosec #Microsoft #Vulnerability #Exploit #Servers #Update #Mitigation #Threat #Risk h

    @dailytechonx

    27 May 2026

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. 🔒 #CyberSecurity CVE-2026-45659: Microsoft SharePoint Unauthenticated RCE — Detection and Remedi… "Unauthenticated RCE in Microsoft SharePoint (CVE-2026-45659). Patch immediately to prevent…" 🔗 https://t.co/lrwpD8J3LG #CyberSecurity #ThreatIntel #cve #zeroday

    @SecurityAr58409

    27 May 2026

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. Top 5 Trending CVEs: 1 - CVE-2026-45659 2 - CVE-2026-5426 3 - CVE-2026-48172 4 - CVE-2024-12802 5 - CVE-2026-8945 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    27 May 2026

    99 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. 🩹マイクロソフト、SharePointの深刻なRCE脆弱性にパッチ(CVE-2026-45659) ⚠️ハッカーがKnowledgeDeliverのゼロデイを悪用し、Webシェルとバックドアを展開(CVE-2026-5426) 〜サイバーアラート5月27日〜 https://t.co/X6yz

    @MachinaRecord

    27 May 2026

    167 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  26. 🚨 HIGH SEVERITY: CVE-2026-45659 (CVSS 8.8) Deserialization flaw in Microsoft SharePoint allows authenticated attackers to execute remote code over network. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR https://t.co/62V8Mrbba0

    @DFIR_Lab

    27 May 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. MicrosoftがSharePointのリモートコード実行脆弱性CVE-2026-45659をサーバーバージョン全体で修正 Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions #HackerNews (May 26) https://t.co/WGO90LPJFj

    @foxbook

    27 May 2026

    213 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. Microsoft patches CVE-2026-45659 in SharePoint, a high-severity RCE flaw tied to untrusted deserialization. Authenticated users with minimal rights could exploit it. #MicrosoftSharePoint #CVE-2026-45659 #MEOW https://t.co/b1k7X8wMUq

    @TweetThreatNews

    26 May 2026

    137 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. 🔒 #CyberSecurity CVE-2026-45659: Microsoft SharePoint Unauthenticated RCE — Detection and Remedi… "Critical unauthenticated RCE (CVE-2026-45659) in Microsoft SharePoint requires immediate…" 🔗 https://t.co/q0QK0mu8iM #CyberSecurity #ThreatIntel #cve #zeroday #patch

    @SecurityAr58409

    26 May 2026

    67 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. 🔬 Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions Vulnerability / Critical CVE: Microsoft has rolled out updates to fix a remote cod... https://t.co/Ef8gRZabgF #CVE #AppSec #CyberSecurity #Privacy

    @MyDooM15

    26 May 2026

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. Microsoft patches SharePoint RCE flaw CVE-2026-45659 (CVSS 8.8) Authenticated attacker (Site Member) bisa execute code remotely. Update sekarang! Artikel: https://t.co/IJvIqaHFju Follow @csalab.id #SharePoint #RCE #CVE #CyberSecurity https://t.co/pXMyHSYHU0

    @csalab_id

    26 May 2026

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  32. Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions https://t.co/jdDr9GpljR

    @VivekIntel

    26 May 2026

    126 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  33. NEW THREAT INTEL: SharePoint Authd RCE (CVE-2026-45659) - .NET deserialization, code exec as w3wp. 9 detections. https://t.co/6P1LmqMG34 #ThreatIntel #SharePoint #CVE https://t.co/gPSsCWq5qM

    @threadlinqs

    26 May 2026

    73 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  34. High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659): Microsoft has released patches for a high-severity remote code execution vulnerability (CVE-2026-45659) in SharePoint that may be exploited in low-complexity attacks. It affects the… https://t.co/6ZVh4JKjCR

    @shah_sheikh

    26 May 2026

    66 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. Urgent SharePoint Patch: Fix Remote Code Execution Flaw CVE-2026-45659 https://t.co/JWRi3E4hZN #Cybertrending #Cybernewsdaily #Cybersecurity

    @unknownmatter19

    24 May 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. Urgent SharePoint Patch: Fix Remote Code Execution Flaw CVE-2026-45659 https://t.co/C3IoJNGEjS #Cybertrending #Cybernewsdaily #Cybersecurity

    @CyberInsights1

    24 May 2026

    3 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations