CVE Tools
Back to feed
Exploited in the wild Microsoft SharePoint Server rce Microsoft

CISA: Microsoft SharePoint RCE flaw now actively exploited

BleepingComputer·By Sergiu Gatlan··2 min read
CVE Tools coverage

CISA says attackers are now actively using a high-severity remote code execution weakness in Microsoft SharePoint, tracked as CVE-2026-45659. The issue is caused by unsafe deserialization of untrusted data and can let authenticated attackers with minimal permissions run arbitrary code on unpatched SharePoint servers via low-complexity, network-based attacks. Microsoft has released fixes for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition, and CISA has added CVE-2026-45659 to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to patch by the applicable deadline.