CVE Tools
Back to feed
Exploited in the wild SharePoint Server rce Microsoft web-app

SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation

The Hacker News·By The Hacker News··3 min read
CVE Tools coverage

CISA has added the Microsoft SharePoint Server remote code execution flaw CVE-2026-45659 (CVSS 8.8) to its Known Exploited Vulnerabilities (KEV) catalog, citing indications that it is being actively exploited in the wild. The issue stems from deserialization of untrusted data and allows an authenticated attacker to run code remotely without requiring admin rights; Microsoft fixed it in May 2026 for SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. This matters because it raises the priority for patching—CISA advises Federal Civilian Executive Branch agencies to remediate by July 4, 2026.