CVE-2026-45659

Published May 22, 2026

Last updated 19 days ago

Exploit knownCVSS high 8.8
Microsoft Office SharePoint
Network
Server

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-45659 is a remote code execution (RCE) vulnerability found in Microsoft SharePoint Server, stemming from a deserialization of untrusted data issue. This flaw allows an authenticated attacker with low privileges, such as a Site Member, to execute arbitrary code on the server without requiring user interaction. The vulnerability affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Despite Microsoft initially assessing the vulnerability as "less likely to be exploited," the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-45659 to its Known Exploited Vulnerabilities (KEV) catalog in July 2026, confirming active exploitation in the wild. A patch for this vulnerability was included in the May 2026 security updates, though its details were inadvertently omitted from the initial release notes.

Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Source
secure@microsoft.com
NVD status
Analyzed
Products
sharepoint_server

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Exploit added on
Jul 1, 2026
Exploit action due
Jul 4, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

secure@microsoft.com
CWE-502

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

5

  1. CVE-2026-45659. CVE-2026-45659 added to CISA KEV: Microsoft SharePoint Server

    @lyrie_ai

    20 Jul 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. 00:00 UTC: CVE-2026-45659 disclosed. CISA: CVE-2026-45659 added to Known Exploited Vulnerabilities — Microsoft SharePoint Server CVE-2026-45659 added to CISA KEV: Microsoft SharePoint Server

    @lyrie_ai

    20 Jul 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. SharePoint CVEs FAQ: CVE-2026-56164, CVE-2026-32201, CVE-2026-45659 | Tenable® https://t.co/SRRYYVs3Jv

    @endi24

    19 Jul 2026

    2542 Impressions

    5 Retweets

    23 Likes

    18 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/denoKmLMkf https://t.co/lvM94DeVpG

    @EAlexStark

    17 Jul 2026

    69 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/Qr0dCd19Nh https://t.co/wD4LUwwYHc

    @dansantanna

    17 Jul 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Four on-premises SharePoint Server CVEs are actively exploited: CVE-2026-32201 (CVSS 6.5), CVE-2026-45659 (CVSS 8.8), CVE-2026-56164 (CVSS 9.8), and CVE-2026-58644 (CVSS 9.8). #DFIR_Radar https://t.co/ln2QdK28Q8

    @DFIR_Radar

    17 Jul 2026

    190 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    2 Replies

    0 Quotes

  7. CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Exploitation Warnings for SharePoint Server Demand Immediate Action https://t.co/uVEGqZq5Sn #CVE2026 #SharePoint #CyberSecurity

    @cyber_newsroom

    16 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. These security flaws (tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) affect all supported self-hosted SharePoint Server versions. https://t.co/q9ukzEgfYf

    @jbhall56

    15 Jul 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🔒 #CyberSecurity CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: SharePoint Server Active Exploi… "On July 14, 2026, CISA issued an urgent alert regarding active exploitation of…" 🔗 https://t.co/A0C48eSEX9 #CyberSecurity #ThreatIntel #managedsoc #mdr #securitymonito

    @SecurityAr58409

    15 Jul 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. CISA warns SharePoint vulnerabilities CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 are exploited in the wild. Patch and harden servers now. #CISA #SharePoint #Microsoft #CVE #CyberSecurity https://t.co/SN49kOAPnL

    @Daily_CyberSec

    15 Jul 2026

    375 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  11. Adobe ColdFusionのPath Traversal脆弱性 CVE-2026-48282、そしてMicrosoft SharePoint ServerのDeserializationの脆弱性 CVE-2026-45659もKEVの是正期限が過ぎています。これらも任...

    @Joe_Biden_ja

    11 Jul 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🛑 SharePoint CVE-2026-45659 active exploitation puts on-prem servers on u… CISA added SharePoint Server CVE-2026-45659 to KEV after active exploitation. Defenders sho… 🔗 Details → https://t.co/DjxT4dttNT

    @lucasverdan

    6 Jul 2026

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. CVE-2026-45659: SharePoint deserialization RCE (CVSS 8.8) on CISA KEV. Only needs Site Member perms. Microsoft rated 'Exploitation Less Likely' — CISA proved otherwise. FCEB patch deadline was July 4. On-prem SharePoint? Patch. Now. #InfoSec #CVE #Cybersecurity

    @infrasecserv

    5 Jul 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. CVE-2026-45659: SharePoint RCE, CVSS 8.8, now on CISA KEV. Patched in May, disclosed a few weeks later, confirmed actively exploited since. A reminder that patch timing and disclosure timing don't always line up, and that gap matters for VM prioritization. #CVE #CyberSecurity

    @ssomya395

    5 Jul 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. CISA warns of actively exploited SharePoint RCE (CVE-2026-45659), demanding immediate patches. This network vulnerability seriously impacts data privacy & integrity in transit. Vigilance is critical! #Cybersecurity #NetworkSecurity #CVE

    @YourAnon_irc

    4 Jul 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. fake poc github: hxxps[://]github[.]com/mistbarbarianspot/CVE-2026-45659-SharePoint-RCE CVE-2026-45659

    @UK_Daniel_Card

    3 Jul 2026

    2417 Impressions

    1 Retweet

    6 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  17. CVE-2026-45659 - Edward Snowden's (The SharePoint admin) fave platform has a CVE... it's in CISA KEV! https://t.co/dByWYfNhD5 https://t.co/6Z5w94QTCG

    @UK_Daniel_Card

    3 Jul 2026

    12705 Impressions

    19 Retweets

    160 Likes

    86 Bookmarks

    3 Replies

    0 Quotes

  18. Legacy exposure keeps paying off for attackers. SharePoint CVE-2026-45659 active exploitation puts on-pre… CISA added SharePoint Server CVE-2026-45659 to KEV after active exploitation. Defenders sho… 🔗 Read → https://t.co/97l4UhUCeq

    @fynn_JourX

    3 Jul 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. For defenders, sharepoint cve-2026-45659 active exploitation puts on-prem serv… should move fast. CISA added SharePoint Server CVE-2026-45659 to KEV after active exploitation. Defenders sho… 🔗 Details → https://t.co/EpEDDraMJk

    @SocXAInvaders

    3 Jul 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. $MSFT flaw by July 4. CISA added CVE-2026-45659 (CVSS 8.8) to its KEV list. Any authenticated user with basic Site Member rights can run code on-prem. Attacker and method remain unknown.$MSFT flaw by July 4. CISA added CVE-2026-45659 (CVSS 8.8) to its KEV list. Any authenticated

    @ShortInfoNews

    2 Jul 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  21. ❗ SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation Critical CVE / Exploit: The U.S. Cybersecurity and Infrastructure Security A... https://t.co/zKDRvBs8Qv #CVE #CyberSecurity #InfoSec #Cybersecurity

    @MyDooM15

    2 Jul 2026

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. 🛡️ CVE-2026-45659: Vulnerabilidad Crítica de Deserialización en Microsoft SharePoint Server Explotada Activamente Análisis técnico del CVE-2026-45659 en Microsoft SharePoint Server: deserialización de datos no confiables con CVSS 8.8 explotada activamente. Mitigaciones

    @CiberPlanetaOrg

    1 Jul 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. Microsoft June 2026 Patch Tuesday is live. Exchange CVE-2026-42897 (CVSS 8.1, actively exploited OWA spoofing): permanent patch replaces the EMES temporary mitigation. SharePoint CVE-2026-45659 (CVSS 8.8 RCE) also drops today. Secure Boot legacy UEFI certs expire June 24.

    @XavierRiveraX

    9 Jun 2026

    116 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. 🚨 CVE-2026-45659: Microsoft SharePoint Server RCE flaw patched. The vulnerability is caused by deserialization of untrusted data and may allow authenticated attackers https://t.co/1Wg7XVYZyo #SharePoint #CVE #RCE #CyberSecurity #Vulert

    @vulert_official

    1 Jun 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. ثغرة تنفيذ كود عن بُعد في خادم مشاركة المحتوى المؤسسي يمكن استغلالها دون شروط خاصة، رُقّعت هذا الأسبوع المعرّف : CVE-2026-45659 درجة الخطورة : 8.8 (CVSS) - Important المن

    @KasperskyDev

    31 May 2026

    67 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions. The vulnerability, tracked as CVE-2026-45659, carries a CVSS score of 8.8. It has been assigned an important severity. https://t.co/cDnGNRpGrC https://t.co/AbtzvOk976

    @riskigy

    30 May 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. Microsoft SharePoint RCE Flaw (CVE-2026-45659, CVSS 8.8) Patched Out-of-Band #cybersecurity #Microsoft #SharePoint #vulnerability #patchnow #enterprisesecurity https://t.co/Nnhx4eN4ET

    @JNitterauer

    28 May 2026

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. 🚨 Guía de remediación urgente: #Vulnerabilidad RCE en #SharePoint (CVE-2026-45659) https://t.co/ZiQr2jUmXG

    @newstecnicas

    28 May 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. CISO Daily Briefing: Gitea CVE-2026-27771 left 30,000+ self-hosted instances silently leaking private container images — healthcare, aerospace, ISPs affected — for nearly 4 years; Microsoft SharePoint CVE-2026-45659 is critical RCE for enterprise deployments; HiddenLayer's 20

    @cloudsa

    28 May 2026

    164 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. ثغرة في خوادم منصة شهيرة لإدارة المحتوى المؤسسي تسمح لمهاجم بأدنى صلاحيات عضو موقع بتنفيذ كود عن بُعد عبر إلغاء تسلسل بيانات غير موثوقة. المنتج : Microsoft Share

    @KasperskyDev

    28 May 2026

    184 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  31. Top 5 Trending CVEs: 1 - CVE-1999-0997 2 - CVE-2026-45659 3 - CVE-2026-23652 4 - CVE-2026-45585 5 - CVE-2024-52577 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    28 May 2026

    98 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  32. Critical #SharePointServer vulnerability (CVE-2026-45659) allows remote code execution. Apply patches immediately to secure your systems. #SharePoint #CVE #RCE #Patch #Security #Cybersecurity #Infosec #Microsoft #Vulnerability #Exploit #Servers #Update #Mitigation #Threat #Risk h

    @dailytechonx

    27 May 2026

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. 🔒 #CyberSecurity CVE-2026-45659: Microsoft SharePoint Unauthenticated RCE — Detection and Remedi… "Unauthenticated RCE in Microsoft SharePoint (CVE-2026-45659). Patch immediately to prevent…" 🔗 https://t.co/lrwpD8J3LG #CyberSecurity #ThreatIntel #cve #zeroday

    @SecurityAr58409

    27 May 2026

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. Top 5 Trending CVEs: 1 - CVE-2026-45659 2 - CVE-2026-5426 3 - CVE-2026-48172 4 - CVE-2024-12802 5 - CVE-2026-8945 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    27 May 2026

    99 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. 🩹マイクロソフト、SharePointの深刻なRCE脆弱性にパッチ(CVE-2026-45659) ⚠️ハッカーがKnowledgeDeliverのゼロデイを悪用し、Webシェルとバックドアを展開(CVE-2026-5426) 〜サイバーアラート5月27日〜 https://t.co/X6yz

    @MachinaRecord

    27 May 2026

    167 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  36. 🚨 HIGH SEVERITY: CVE-2026-45659 (CVSS 8.8) Deserialization flaw in Microsoft SharePoint allows authenticated attackers to execute remote code over network. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR https://t.co/62V8Mrbba0

    @DFIR_Lab

    27 May 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. MicrosoftがSharePointのリモートコード実行脆弱性CVE-2026-45659をサーバーバージョン全体で修正 Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions #HackerNews (May 26) https://t.co/WGO90LPJFj

    @foxbook

    27 May 2026

    213 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. Microsoft patches CVE-2026-45659 in SharePoint, a high-severity RCE flaw tied to untrusted deserialization. Authenticated users with minimal rights could exploit it. #MicrosoftSharePoint #CVE-2026-45659 #MEOW https://t.co/b1k7X8wMUq

    @TweetThreatNews

    26 May 2026

    137 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. 🔒 #CyberSecurity CVE-2026-45659: Microsoft SharePoint Unauthenticated RCE — Detection and Remedi… "Critical unauthenticated RCE (CVE-2026-45659) in Microsoft SharePoint requires immediate…" 🔗 https://t.co/q0QK0mu8iM #CyberSecurity #ThreatIntel #cve #zeroday #patch

    @SecurityAr58409

    26 May 2026

    67 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. 🔬 Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions Vulnerability / Critical CVE: Microsoft has rolled out updates to fix a remote cod... https://t.co/Ef8gRZabgF #CVE #AppSec #CyberSecurity #Privacy

    @MyDooM15

    26 May 2026

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  41. Microsoft patches SharePoint RCE flaw CVE-2026-45659 (CVSS 8.8) Authenticated attacker (Site Member) bisa execute code remotely. Update sekarang! Artikel: https://t.co/IJvIqaHFju Follow @csalab.id #SharePoint #RCE #CVE #CyberSecurity https://t.co/pXMyHSYHU0

    @csalab_id

    26 May 2026

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  42. Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions https://t.co/jdDr9GpljR

    @VivekIntel

    26 May 2026

    126 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  43. NEW THREAT INTEL: SharePoint Authd RCE (CVE-2026-45659) - .NET deserialization, code exec as w3wp. 9 detections. https://t.co/6P1LmqMG34 #ThreatIntel #SharePoint #CVE https://t.co/gPSsCWq5qM

    @threadlinqs

    26 May 2026

    73 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  44. High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659): Microsoft has released patches for a high-severity remote code execution vulnerability (CVE-2026-45659) in SharePoint that may be exploited in low-complexity attacks. It affects the… https://t.co/6ZVh4JKjCR

    @shah_sheikh

    26 May 2026

    66 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  45. Urgent SharePoint Patch: Fix Remote Code Execution Flaw CVE-2026-45659 https://t.co/JWRi3E4hZN #Cybertrending #Cybernewsdaily #Cybersecurity

    @unknownmatter19

    24 May 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. Urgent SharePoint Patch: Fix Remote Code Execution Flaw CVE-2026-45659 https://t.co/C3IoJNGEjS #Cybertrending #Cybernewsdaily #Cybersecurity

    @CyberInsights1

    24 May 2026

    3 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations