CVE Tools

SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation

The Hacker NewsBy The Hacker News

Reported exploitedSharePoint Server

Our summary

CISA has added the Microsoft SharePoint Server remote code execution flaw CVE-2026-45659 (CVSS 8.8) to its Known Exploited Vulnerabilities (KEV) catalog, citing indications that it is being actively exploited in the wild. The issue stems from deserialization of untrusted data and allows an authenticated attacker to run code remotely without requiring admin rights; Microsoft fixed it in May 2026 for SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. This matters because it raises the priority for patching—CISA advises Federal Civilian Executive Branch agencies to remediate by July 4, 2026.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store