SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation

Citing indications of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a high-severity vulnerability affecting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) list on Wednesday.

The vulnerability, identified as CVE-2026-45659 (CVSS score: 8.8), involves the deserialization of untrusted data, which can lead to remote code execution. Microsoft fixed the problem in SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016 in May 2026.

Microsoft stated that the vulnerability does not require admin or other elevated access and that it could be triggered by any authenticated attacker. An authenticated attacker with at least Site Member permissions (PR:L) might use it to remotely run code on the SharePoint Server in a network-based assault.

According to CISA, Microsoft SharePoint Server has a deserialization of untrusted data vulnerability that lets an authorized attacker run code across a network read more about SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *