SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
Reported exploitedSharePoint ServerOur summary
CISA has added the Microsoft SharePoint Server remote code execution flaw CVE-2026-45659 (CVSS 8.8) to its Known Exploited Vulnerabilities (KEV) catalog, citing indications that it is being actively exploited in the wild. The issue stems from deserialization of untrusted data and allows an authenticated attacker to run code remotely without requiring admin rights; Microsoft fixed it in May 2026 for SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. This matters because it raises the priority for patching—CISA advises Federal Civilian Executive Branch agencies to remediate by July 4, 2026.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.