CVE-2026-45659

Published May 22, 2026

Last updated a month ago

Exploit knownCVSS high 8.8
Microsoft Office SharePoint
lms
Network
Zero-day
Server

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-45659 is a remote code execution (RCE) vulnerability found in Microsoft SharePoint Server, stemming from a deserialization of untrusted data issue. This flaw allows an authenticated attacker with low privileges, such as a Site Member, to execute arbitrary code on the server without requiring user interaction. The vulnerability affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Despite Microsoft initially assessing the vulnerability as "less likely to be exploited," the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-45659 to its Known Exploited Vulnerabilities (KEV) catalog in July 2026, confirming active exploitation in the wild. A patch for this vulnerability was included in the May 2026 security updates, though its details were inadvertently omitted from the initial release notes.

Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Source
secure@microsoft.com
NVD status
Analyzed
Products
sharepoint_server

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Exploit added on
Jul 1, 2026
Exploit action due
Jul 4, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

secure@microsoft.com
CWE-502

Social media

Hype score
Not currently trending
  1. 🚨 Guía de remediación urgente: Vulnerabilidad RCE en SharePoint (CVE-2026-45659) https://t.co/ZiQr2jUmXG

    @newstecnicas

    23 Aug 2026

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CISA just added SharePoint RCE CVE-2026-45659 to its KEV catalog. Active exploitation confirmed, now tied to ransomware hitting on-prem SharePoint Server. Patch and hunt now. #CyberSecurity #Ransomware https://t.co/Om10jOwSWU

    @Anavem_

    23 Aug 2026

    82 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Recent SharePoint CVEs (2026) CVE-2026-45659: A high-severity remote code execution flaw affecting on-premises SharePoint Server. It allows authenticated users with basic access to run code, and CISA confirmed active ransomware exploitation. CVE-2026-58644: A critical (CVSS ht

    @FosoTweets

    12 Aug 2026

    102 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Public PoC bypasses Microsoft's July Defender fix and grants SYSTEM on fully patched Win11 and Server 2025. Still unpatched. Eighth zero day from this researcher since April. CISA separately flagged SharePoint CVE-2026-45659 in live ransomware use. https://t.co/mXPhDg3UKn

    @EvanKirstel

    12 Aug 2026

    534 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/Ri70B2BnrO https://t.co/3ua3S2vWb7

    @IT_Peurico

    11 Aug 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 11 new OPEN, 15 new PRO (11 + 4) TA2730, Cisco UCM 15.x Unauth RCE, CVE-2023-29357 (MS Sharepoint Auth Bypass), CVE-2026-45659 (Sharepoint Deserialization RCE), Lumma Stealer, and many more. https://t.co/ejyHRbJocj

    @ET_Labs

    7 Aug 2026

    205 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/SNLFJANHDb https://t.co/noto7ekzQB

    @TechMash365

    5 Aug 2026

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/IdSiTFG29D https://t.co/F6d1bPKsHo

    @Art_Capella

    27 Jul 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/2q9gcGN5tf https://t.co/F84M3Pwt86

    @ggrubamn

    22 Jul 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/dP22TvHKXe https://t.co/hX3St5TYaX

    @pcasano

    21 Jul 2026

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. CVE-2026-45659. CVE-2026-45659 added to CISA KEV: Microsoft SharePoint Server

    @lyrie_ai

    20 Jul 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  12. 00:00 UTC: CVE-2026-45659 disclosed. CISA: CVE-2026-45659 added to Known Exploited Vulnerabilities — Microsoft SharePoint Server CVE-2026-45659 added to CISA KEV: Microsoft SharePoint Server

    @lyrie_ai

    20 Jul 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  13. SharePoint CVEs FAQ: CVE-2026-56164, CVE-2026-32201, CVE-2026-45659 | Tenable® https://t.co/SRRYYVs3Jv

    @endi24

    19 Jul 2026

    2542 Impressions

    5 Retweets

    23 Likes

    18 Bookmarks

    0 Replies

    0 Quotes

  14. CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/denoKmLMkf https://t.co/lvM94DeVpG

    @EAlexStark

    17 Jul 2026

    69 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/Qr0dCd19Nh https://t.co/wD4LUwwYHc

    @dansantanna

    17 Jul 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Four on-premises SharePoint Server CVEs are actively exploited: CVE-2026-32201 (CVSS 6.5), CVE-2026-45659 (CVSS 8.8), CVE-2026-56164 (CVSS 9.8), and CVE-2026-58644 (CVSS 9.8). #DFIR_Radar https://t.co/ln2QdK28Q8

    @DFIR_Radar

    17 Jul 2026

    190 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    2 Replies

    0 Quotes

  17. CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Exploitation Warnings for SharePoint Server Demand Immediate Action https://t.co/uVEGqZq5Sn #CVE2026 #SharePoint #CyberSecurity

    @cyber_newsroom

    16 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. These security flaws (tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) affect all supported self-hosted SharePoint Server versions. https://t.co/q9ukzEgfYf

    @jbhall56

    15 Jul 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. 🔒 #CyberSecurity CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: SharePoint Server Active Exploi… "On July 14, 2026, CISA issued an urgent alert regarding active exploitation of…" 🔗 https://t.co/A0C48eSEX9 #CyberSecurity #ThreatIntel #managedsoc #mdr #securitymonito

    @SecurityAr58409

    15 Jul 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. CISA warns SharePoint vulnerabilities CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 are exploited in the wild. Patch and harden servers now. #CISA #SharePoint #Microsoft #CVE #CyberSecurity https://t.co/SN49kOAPnL

    @Daily_CyberSec

    15 Jul 2026

    375 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  21. Adobe ColdFusionのPath Traversal脆弱性 CVE-2026-48282、そしてMicrosoft SharePoint ServerのDeserializationの脆弱性 CVE-2026-45659もKEVの是正期限が過ぎています。これらも任...

    @Joe_Biden_ja

    11 Jul 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. 🛑 SharePoint CVE-2026-45659 active exploitation puts on-prem servers on u… CISA added SharePoint Server CVE-2026-45659 to KEV after active exploitation. Defenders sho… 🔗 Details → https://t.co/DjxT4dttNT

    @lucasverdan

    6 Jul 2026

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. CVE-2026-45659: SharePoint deserialization RCE (CVSS 8.8) on CISA KEV. Only needs Site Member perms. Microsoft rated 'Exploitation Less Likely' — CISA proved otherwise. FCEB patch deadline was July 4. On-prem SharePoint? Patch. Now. #InfoSec #CVE #Cybersecurity

    @infrasecserv

    5 Jul 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. CVE-2026-45659: SharePoint RCE, CVSS 8.8, now on CISA KEV. Patched in May, disclosed a few weeks later, confirmed actively exploited since. A reminder that patch timing and disclosure timing don't always line up, and that gap matters for VM prioritization. #CVE #CyberSecurity

    @ssomya395

    5 Jul 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. CISA warns of actively exploited SharePoint RCE (CVE-2026-45659), demanding immediate patches. This network vulnerability seriously impacts data privacy & integrity in transit. Vigilance is critical! #Cybersecurity #NetworkSecurity #CVE

    @YourAnon_irc

    4 Jul 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. fake poc github: hxxps[://]github[.]com/mistbarbarianspot/CVE-2026-45659-SharePoint-RCE CVE-2026-45659

    @UK_Daniel_Card

    3 Jul 2026

    2417 Impressions

    1 Retweet

    6 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  27. CVE-2026-45659 - Edward Snowden's (The SharePoint admin) fave platform has a CVE... it's in CISA KEV! https://t.co/dByWYfNhD5 https://t.co/6Z5w94QTCG

    @UK_Daniel_Card

    3 Jul 2026

    12705 Impressions

    19 Retweets

    160 Likes

    86 Bookmarks

    3 Replies

    0 Quotes

  28. Legacy exposure keeps paying off for attackers. SharePoint CVE-2026-45659 active exploitation puts on-pre… CISA added SharePoint Server CVE-2026-45659 to KEV after active exploitation. Defenders sho… 🔗 Read → https://t.co/97l4UhUCeq

    @fynn_JourX

    3 Jul 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. For defenders, sharepoint cve-2026-45659 active exploitation puts on-prem serv… should move fast. CISA added SharePoint Server CVE-2026-45659 to KEV after active exploitation. Defenders sho… 🔗 Details → https://t.co/EpEDDraMJk

    @SocXAInvaders

    3 Jul 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. $MSFT flaw by July 4. CISA added CVE-2026-45659 (CVSS 8.8) to its KEV list. Any authenticated user with basic Site Member rights can run code on-prem. Attacker and method remain unknown.$MSFT flaw by July 4. CISA added CVE-2026-45659 (CVSS 8.8) to its KEV list. Any authenticated

    @ShortInfoNews

    2 Jul 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  31. ❗ SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation Critical CVE / Exploit: The U.S. Cybersecurity and Infrastructure Security A... https://t.co/zKDRvBs8Qv #CVE #CyberSecurity #InfoSec #Cybersecurity

    @MyDooM15

    2 Jul 2026

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. 🛡️ CVE-2026-45659: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Server Explotada Activamente Análisis técnico del CVE-2026-45659 en Microsoft SharePoint Server: deserialización de datos no confiables con CVSS 8.8 explotada activamente. Mitigaciones

    @CiberPlanetaOrg

    1 Jul 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. Microsoft June 2026 Patch Tuesday is live. Exchange CVE-2026-42897 (CVSS 8.1, actively exploited OWA spoofing): permanent patch replaces the EMES temporary mitigation. SharePoint CVE-2026-45659 (CVSS 8.8 RCE) also drops today. Secure Boot legacy UEFI certs expire June 24.

    @XavierRiveraX

    9 Jun 2026

    116 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. 🚨 CVE-2026-45659: Microsoft SharePoint Server RCE flaw patched. The vulnerability is caused by deserialization of untrusted data and may allow authenticated attackers https://t.co/1Wg7XVYZyo #SharePoint #CVE #RCE #CyberSecurity #Vulert

    @vulert_official

    1 Jun 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. ثغرة تنفيذ كود عن بُعد في خادم مشاركة المحتوى المؤسسي يمكن استغلالها دون شروط خاصة، رُقّعت هذا الأسبوع المعرّف : CVE-2026-45659 درجة الخطورة : 8.8 (CVSS) - Important المن

    @KasperskyDev

    31 May 2026

    67 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions. The vulnerability, tracked as CVE-2026-45659, carries a CVSS score of 8.8. It has been assigned an important severity. https://t.co/cDnGNRpGrC https://t.co/AbtzvOk976

    @riskigy

    30 May 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. Microsoft SharePoint RCE Flaw (CVE-2026-45659, CVSS 8.8) Patched Out-of-Band #cybersecurity #Microsoft #SharePoint #vulnerability #patchnow #enterprisesecurity https://t.co/Nnhx4eN4ET

    @JNitterauer

    28 May 2026

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. 🚨 Guía de remediación urgente: #Vulnerabilidad RCE en #SharePoint (CVE-2026-45659) https://t.co/ZiQr2jUmXG

    @newstecnicas

    28 May 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. CISO Daily Briefing: Gitea CVE-2026-27771 left 30,000+ self-hosted instances silently leaking private container images — healthcare, aerospace, ISPs affected — for nearly 4 years; Microsoft SharePoint CVE-2026-45659 is critical RCE for enterprise deployments; HiddenLayer's 20

    @cloudsa

    28 May 2026

    164 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. ثغرة في خوادم منصة شهيرة لإدارة المحتوى المؤسسي تسمح لمهاجم بأدنى صلاحيات عضو موقع بتنفيذ كود عن بُعد عبر إلغاء تسلسل بيانات غير موثوقة. المنتج : Microsoft Share

    @KasperskyDev

    28 May 2026

    184 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  41. Top 5 Trending CVEs: 1 - CVE-1999-0997 2 - CVE-2026-45659 3 - CVE-2026-23652 4 - CVE-2026-45585 5 - CVE-2024-52577 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    28 May 2026

    98 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  42. Critical #SharePointServer vulnerability (CVE-2026-45659) allows remote code execution. Apply patches immediately to secure your systems. #SharePoint #CVE #RCE #Patch #Security #Cybersecurity #Infosec #Microsoft #Vulnerability #Exploit #Servers #Update #Mitigation #Threat #Risk h

    @dailytechonx

    27 May 2026

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. 🔒 #CyberSecurity CVE-2026-45659: Microsoft SharePoint Unauthenticated RCE — Detection and Remedi… "Unauthenticated RCE in Microsoft SharePoint (CVE-2026-45659). Patch immediately to prevent…" 🔗 https://t.co/lrwpD8J3LG #CyberSecurity #ThreatIntel #cve #zeroday

    @SecurityAr58409

    27 May 2026

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. Top 5 Trending CVEs: 1 - CVE-2026-45659 2 - CVE-2026-5426 3 - CVE-2026-48172 4 - CVE-2024-12802 5 - CVE-2026-8945 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    27 May 2026

    99 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. 🩹マイクロソフト、SharePointの深刻なRCE脆弱性にパッチ(CVE-2026-45659) ⚠️ハッカーがKnowledgeDeliverのゼロデイを悪用し、Webシェルとバックドアを展開(CVE-2026-5426) 〜サイバーアラート5月27日〜 https://t.co/X6yz

    @MachinaRecord

    27 May 2026

    167 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  46. 🚨 HIGH SEVERITY: CVE-2026-45659 (CVSS 8.8) Deserialization flaw in Microsoft SharePoint allows authenticated attackers to execute remote code over network. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR https://t.co/62V8Mrbba0

    @DFIR_Lab

    27 May 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  47. MicrosoftがSharePointのリモートコード実行脆弱性CVE-2026-45659をサーバーバージョン全体で修正 Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions #HackerNews (May 26) https://t.co/WGO90LPJFj

    @foxbook

    27 May 2026

    213 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. Microsoft patches CVE-2026-45659 in SharePoint, a high-severity RCE flaw tied to untrusted deserialization. Authenticated users with minimal rights could exploit it. #MicrosoftSharePoint #CVE-2026-45659 #MEOW https://t.co/b1k7X8wMUq

    @TweetThreatNews

    26 May 2026

    137 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  49. 🔒 #CyberSecurity CVE-2026-45659: Microsoft SharePoint Unauthenticated RCE — Detection and Remedi… "Critical unauthenticated RCE (CVE-2026-45659) in Microsoft SharePoint requires immediate…" 🔗 https://t.co/q0QK0mu8iM #CyberSecurity #ThreatIntel #cve #zeroday #patch

    @SecurityAr58409

    26 May 2026

    67 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  50. 🔬 Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions Vulnerability / Critical CVE: Microsoft has rolled out updates to fix a remote cod... https://t.co/Ef8gRZabgF #CVE #AppSec #CyberSecurity #Privacy

    @MyDooM15

    26 May 2026

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations