Exploited in the wild Microsoft SharePoint Server rce Microsoft
CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability
CVE Tools coverage
CISA says attackers are already exploiting a high-severity Microsoft SharePoint Server vulnerability that stems from unsafe deserialization of untrusted data (CVE-2026-45659, CVSS 8.8). The issue can allow an authenticated attacker with at least Site Member permissions to run arbitrary code on affected SharePoint servers, which makes it particularly dangerous and easy to repeat in practice. SharePoint Server Subscription Edition, SharePoint Server 2019, SharePoint Server 2016, and SharePoint Enterprise Server 2016 are affected, and CISA added CVE-2026-45659 to its KEV catalog with an expectation that federal agencies patch within three days.