CVE Tools

CISA: Microsoft SharePoint RCE flaw now actively exploited

BleepingComputerBy Sergiu Gatlan

Reported exploitedMicrosoft SharePoint Server

Our summary

CISA says attackers are now actively using a high-severity remote code execution weakness in Microsoft SharePoint, tracked as CVE-2026-45659. The issue is caused by unsafe deserialization of untrusted data and can let authenticated attackers with minimal permissions run arbitrary code on unpatched SharePoint servers via low-complexity, network-based attacks. Microsoft has released fixes for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition, and CISA has added CVE-2026-45659 to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to patch by the applicable deadline.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store