The active exploitation of CVE-2026-45659 highlights the continuing risk posed by vulnerabilities in on-premises Microsoft SharePoint environments.
The flaw results from unsafe deserialization and can allow an attacker with low-level SharePoint access to execute arbitrary code on the affected server. Exploitation is considered relatively simple and does not require user interaction.
Affected products include SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. SharePoint Online is not affected.
Organizations should immediately apply Microsoft’s security updates and restrict SharePoint access to trusted users and networks. Internet-facing deployments should receive the highest priority because attackers are already exploiting the vulnerability.
Since valid low-privilege access is required, organizations should also review compromised, dormant, contractor, and service accounts. Multifactor authentication, least-privilege permissions, and continuous monitoring of authenticated activity remain important.
Patching should be followed by an investigation for unusual application activity, unexpected processes, newly created files or accounts, configuration changes, web shells, and abnormal outbound connections.
The key lesson is that a low-privilege SharePoint account should not be dismissed as harmless. When combined with a code-execution vulnerability, limited access can quickly become control of a server containing sensitive documents, credentials, and connections to the wider enterprise network.
CISA warned on Wednesday that attackers have begun exploiting a high-severity Microsoft SharePoint remote code execution vulnerability patched in May. [...]
Source: CISA: Microsoft SharePoint RCE flaw now actively exploited via Bleeping Computer — published 02 Jul 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.