CVE-2026-45659
Microsoft SharePoint Remote Code Execution Vulnerability
Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
In plain language
AI Act nowCVE-2026-45659 is a SharePoint Server flaw that lets an attacker run code on your server if they already have a low-privilege SharePoint account; typical small businesses should treat it as urgent to patch now.
CVE-2026-45659 is a Microsoft SharePoint Server remote code execution issue triggered by deserialization of untrusted data, allowing authenticated attackers with minimal permissions (Site Member) to execute code; it is confirmed in the CISA KEV catalog with active exploitation, so organizations using the affected SharePoint Server products must patch to the fixed builds listed.
What to do now
- Check whether your organization runs Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server, or Microsoft SharePoint Server 2019, and determine your current SharePoint build number.
- Compare your build against the fixed versions: SharePoint Server fixed in 16.0.19725.20280; SharePoint Enterprise Server 2016 fixed in 16.0.5552.1002; SharePoint Server 2019 fixed in 16.0.10417.20128.
- Install the Microsoft SharePoint security update(s) for CVE-2026-45659 per the Microsoft update guide, upgrading to the corresponding fixed build(s).
- If you cannot patch immediately, contact Microsoft support/vendor guidance and follow CISA KEV instructions to apply available mitigations or discontinue use until mitigations are in place, especially for assets exposed to the internet.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
- Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacksen-us·SecurityWeek· Exploited SharePoint Server network-edge
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoCen·The Hacker News· Exploited SharePoint Server rce
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEVen·The Hacker News· Exploited SharePoint Server Subscription Edition rce
- CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilitiesen-us·SecurityWeek· Exploited Microsoft SharePoint zero-day
- Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesdayen·The Hacker News· PoC Windows User Profile Service (ProfSvc) Chaotic Eclipse
- AI-driven bug hunting fuels record Microsoft Patch Tuesdayen-us·Help Net Security· Exploited Windows patch-tuesday
- CISA warns admins to patch actively exploited SharePoint flawsen-us·BleepingComputer· Exploited SharePoint Server rce
- CISA: Microsoft SharePoint RCE flaw now actively exploiteden-us·BleepingComputer· Exploited Microsoft SharePoint Server rce
- CISA Warns of Actively Exploited Microsoft SharePoint Vulnerabilityen-us·SecurityWeek· Exploited Microsoft SharePoint Server rce
- SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitationen·The Hacker News· Exploited SharePoint Server rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-45659 and every CVE in our database. Create a free account — no credit card required.
Create Free Account