CISA’s addition of CVE-2026-45659 to its Known Exploited Vulnerabilities catalogue confirms that attackers are actively exploiting the Microsoft SharePoint flaw in real environments.

The vulnerability affects on-premises SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. SharePoint Online is not affected.

The flaw results from unsafe deserialization and allows an authenticated attacker with only low-level permissions to execute arbitrary code remotely. This means a compromised ordinary user account may be enough to take control of the SharePoint server.

Organizations should apply Microsoft’s May 2026 security updates immediately. CISA has directed applicable U.S. federal agencies to remediate the vulnerability by July 4, 2026, but private organizations should treat the same deadline as an indication of urgency.

Since exploitation is already occurring, patching should be followed by an investigation. Administrators should review SharePoint and operating-system logs for unusual activity, unexpected files, web shells, suspicious processes, new accounts, configuration changes, and abnormal outbound connections.

Dormant, contractor, service, and low-privilege accounts should also be reviewed because the vulnerability does not require administrator access. Internet-facing SharePoint systems should be restricted to trusted users and networks wherever possible.

The key lesson is that “low privilege” does not mean “low risk.” When combined with a remote code-execution vulnerability, one stolen SharePoint account can become control of a server containing sensitive documents, credentials, and access to the wider enterprise network.


The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-45659 (CVSS score: 8.8), is a case of remote code execution arising from the deserialization of untrusted data. The issue

Source: SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation via The Hacker News — published 02 Jul 2026.