The Cybersecurity and Infrastructure Security Agency has added a critical remote code execution vulnerability in Microsoft SharePoint Server to its Known Exploited Vulnerabilities catalog. The flaw, tracked as CVE-2026-45659, is being actively exploited and poses a significant risk to organizations running unpatched SharePoint servers.

CISA's action triggers binding operational directive requirements for federal agencies, which must patch the vulnerability by specified deadlines. Private sector organizations are strongly encouraged to apply Microsoft's security updates as quickly as possible.

What Happened: CVE-2026-45659 Added to CISA's KEV Catalog

CISA added CVE-2026-45659 to the KEV catalog after confirming active exploitation in the wild. The vulnerability is a remote code execution flaw in Microsoft SharePoint Server caused by deserialization of untrusted data. Microsoft had addressed the flaw in its May 2026 security updates.

The vulnerability carries a CVSS score of 8.8, indicating high severity. Successful exploitation allows attackers to execute arbitrary code on affected SharePoint servers without authentication.

Key Details

SharePoint Server is widely deployed in enterprise environments for document management and collaboration. A remote code execution vulnerability in this platform is particularly dangerous because SharePoint servers typically contain sensitive business documents and integrate with other enterprise systems.

Deserialization vulnerabilities occur when applications unsafely process serialized data from untrusted sources. Attackers can craft malicious serialized objects that execute code when deserialized by the vulnerable application.

Why It Matters

Active exploitation of a SharePoint RCE vulnerability means that attackers are already using it to compromise organizations. Any organization running unpatched SharePoint Server is at immediate risk.

The CISA KEV catalog addition is significant because it reflects confirmed real-world exploitation, not just theoretical risk. Federal agencies face mandatory patching timelines, and the inclusion serves as a strong signal to all organizations about the urgency.

Industry Context

Microsoft SharePoint has been a frequent target for attackers due to its widespread deployment and the valuable data it contains. Previous SharePoint vulnerabilities have been exploited by nation-state actors and ransomware groups to gain initial access to enterprise networks.

CISA's KEV catalog has become a key resource for vulnerability prioritization. Security teams increasingly use KEV inclusion as a primary signal for which patches to apply first.

What It Means for Users and the Industry

For SharePoint administrators, immediate patching is essential. Organizations should verify that their SharePoint installations have received the May 2026 security updates. If patching is delayed, temporary mitigations such as restricting SharePoint access may be necessary.

For the broader security community, this vulnerability reinforces the importance of timely patch management for internet-facing enterprise applications.

What Happens Next

Microsoft has already released patches. CISA will monitor compliance from federal agencies. Attackers will likely continue exploiting unpatched systems until the vulnerable population shrinks significantly.

Final Takeaway

CVE-2026-45659 is a serious, actively exploited vulnerability in a widely deployed enterprise platform. Organizations running SharePoint Server should treat patching as a critical priority.

SharePoint as an Attack Target

Microsoft SharePoint Server is an attractive target for attackers because it is widely deployed in enterprises and contains valuable business documents. A successful compromise can provide access to intellectual property, financial records, strategic plans, and employee information. SharePoint's integration with other Microsoft services also means that a SharePoint compromise can serve as a pivot point to broader network access.

The deserialization vulnerability in CVE-2026-45659 is particularly dangerous because it can be exploited without authentication. Attackers do not need valid credentials or prior access to attempt exploitation. This makes internet-facing SharePoint servers especially vulnerable to automated scanning and exploitation.

Organizations should also review their SharePoint configurations to ensure that servers are not unnecessarily exposed to the internet. SharePoint installations intended for internal use should be accessible only from internal networks or through VPN connections.

FAQs

What is deserialization?
Deserialization is the process of converting serialized data back into objects. Unsafe deserialization occurs when an application processes untrusted serialized data without proper validation.
Can this vulnerability be exploited remotely?
Yes, the vulnerability can be exploited remotely without authentication, making it particularly dangerous for internet-facing SharePoint servers.
When were patches released?
Microsoft addressed this vulnerability in its May 2026 security updates.
What is the CVSS severity score for CVE-2026-45659?
The vulnerability carries a CVSS score of 8.8, indicating high severity, and allows attackers to execute arbitrary code on affected SharePoint servers without authentication.
Are federal agencies required to patch this vulnerability?
Yes, CISA's KEV catalog addition triggers binding operational directive requirements that give federal agencies mandatory patching deadlines.
What should I do if I can't patch SharePoint immediately?
Restrict SharePoint access to internal networks or VPN connections as a temporary mitigation, and prioritize applying Microsoft's May 2026 security updates as soon as possible.

Sources and Verification

  1. CISA KEV Catalog, July 2026
  2. BleepingComputer

This article was reviewed as part of CapisTech's editorial fact-checking process.

CISASharePointRCEVulnerabilityCybersecurity