CVE Tools

CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability

SecurityWeekBy Ionut Arghire

Reported exploitedMicrosoft SharePoint Server

Our summary

CISA says attackers are already exploiting a high-severity Microsoft SharePoint Server vulnerability that stems from unsafe deserialization of untrusted data (CVE-2026-45659, CVSS 8.8). The issue can allow an authenticated attacker with at least Site Member permissions to run arbitrary code on affected SharePoint servers, which makes it particularly dangerous and easy to repeat in practice. SharePoint Server Subscription Edition, SharePoint Server 2019, SharePoint Server 2016, and SharePoint Enterprise Server 2016 are affected, and CISA added CVE-2026-45659 to its KEV catalog with an expectation that federal agencies patch within three days.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store