CVE-2026-45659
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability - [Actively Exploited]
Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
INFO
Published Date :
May 22, 2026, 11:16 p.m.
Last Modified :
July 23, 2026, 11:10 a.m.
Remotely Exploit :
No
Source :
[email protected]
CISA KEV (Known Exploited Vulnerabilities)
For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Unknown
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-45659
Affected Products
The following products are affected by CVE-2026-45659
vulnerability.
Even if cvefeed.io is aware of the exact versions of the
products
that
are
affected, the information is not represented in the table below.
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | |||||
| CVSS 3.1 | HIGH | f38d906d-7342-40ea-92c1-6c4a2c6478c8 | ||||
| CVSS 3.1 | HIGH | [email protected] |
Public PoC/Exploit Available at Github
CVE-2026-45659 has a 14 public
PoC/Exploit available at Github.
Go to the Public Exploits tab to see the list.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-45659.
| URL | Resource |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-45659 | US Government Resource |
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-45659 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-45659
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
End-to-end technical analysis and reproduction notes for high-impact CVEs (e.g., pre-auth RCEs, sandbox escapes, and privilege escalations).
Cybersecurity research notes on threat intelligence, vulnerabilities, incident response, detection ideas, and SOC analyst learning.
cve cybersecurity detection-engineering incident-response malware-analysis mitre-attack security-operations security-research siem soc threat-intelligence vulnerability-management
Professional vulnerability assessment report for SharePoint deserialization risk, including executive summary, technical impact, remediation, and mitigation strategy.
cve-analysis remediation root-cause-analysis security-research technical-writing vulnerability-research
Python
MCP server for Purify security-intelligence feeds (CISA KEV / EPSS) with per-record provenance
cisa-kev claude cve epss mcp mcp-server security-intelligence
Go
None
JavaScript Makefile HTML TypeScript Shell CSS
주요 CVE 분석
None
None
None
Python
CVE-2026-45659
Python
Audit CVE impact, patch status, remediation progress, and verification results across systems.
Makefile Go
An operational threat hunting and detection suite. Maps network and host log queries directly to the MITRE ATT&CK framework, featuring an evidence-driven attribution engine that dynamically correlates indicators to state-sponsored threat actors.
HTML CSS JavaScript
The difference between exploitation prediction and detection is akin to the difference between detecting a missile launch or a detonation. Every avoided exploitation cycle saves hundreds of hours of engineering and infosec time.
Jupyter Notebook Python PowerShell
📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
security cve exploit poc vulnerability
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-45659 vulnerability anywhere in the article.
-
The Hacker News
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 ... Read more
-
security.nl
Microsoft meldt alsnog actief misbruik van kritiek SharePoint-lek
Een kritieke kwetsbaarheid in Microsoft SharePoint waardoor aanvallers SharePoint-servers op afstand kunnen overnemen is toch wel actief bij aanvallen misbruikt voordat een beveiligingsupdate beschikb ... Read more
-
The Hacker News
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) cata ... Read more
-
The Hacker News
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described as a Windows User Profile Service arbitrary hive ... Read more
-
security.nl
Microsoft SharePoint-servers aangevallen, VS roept op tot extra beveiliging
Aanvallers maken actief misbruik van verschillende kwetsbaarheden voor het aanvallen van Microsoft SharePoint-servers, zo waarschuwt het Amerikaanse cyberagentschap CISA. Dat roept organisaties op om ... Read more
-
TheCyberThrone
Adobe ColdFusion CVE-2026-48282: Under Active Exploitation
Executive SummaryAdobe has released an emergency security update for CVE-2026-48282, a critical vulnerability affecting Adobe ColdFusion. With a CVSS v3.1 score of 10.0, this vulnerability represents ... Read more
-
TheCyberThrone
JadePuffer: The Dawn of Agentic AI Ransomware
When Artificial Intelligence Stops Assisting Attackers and Starts Becoming the AttackerCybersecurity has long anticipated the day when Artificial Intelligence would transition from being a supporting ... Read more
-
TheCyberThrone
Citrix Fixes 6 Vulnerabilities in NetScaler
July 3, 2026Citrix has released security updates for its widely deployed NetScaler ADC and NetScaler Gateway, patching six vulnerabilities that could expose organizations to arbitrary file reads, memo ... Read more
-
TheCyberThrone
CISA Adds CVE-2026-45659 SharePoint Vulnerability to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (Cybersecurity and Infrastructure Security Agency) has added a critical Microsoft SharePoint vulnerability to its Known Exploited Vulnerabilit ... Read more
-
security.nl
Microsoft SharePoint-servers actief aangevallen via recent beveiligingslek
Een kwetsbaarheid in Microsoft SharePoint waardoor remote code execution (RCE) mogelijk is wordt actief misbruikt bij aanvallen, zo waarschuwt het Amerikaanse cyberagentschap CISA. Microsoft kwam tijd ... Read more
-
The Hacker News
SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, cit ... Read more
-
The Hacker News
WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine
Two Russia-aligned cyber attack campaigns have continued to exploit a security flaw in WinRAR to target Ukrainian organisations, almost a year after patches for the vulnerability were released. The ac ... Read more
-
The Hacker News
Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models
University of Toronto researchers have built and tested a proof-of-concept AI-driven computer worm that uses a locally hosted open-weight large language model to reason its way through a network, gene ... Read more
-
The Hacker News
Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now
Google has released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-11645 (CVSS ... Read more
-
The Hacker News
LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity flaw impacting BerriAI LiteLLM to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of ... Read more
-
The Hacker News
One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public
Security researchers have published a detailed, working exploit for a Linux kernel use-after-free that lets an unprivileged local user escalate to root and break out of a container. The flaw, CVE-2026 ... Read more
-
The Hacker News
Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups
Check Point has warned of active exploitation of a critical vulnerability impacting Remote Access VPN and Mobile Access deployments that are configured to use the deprecated IKEv1 key exchange protoco ... Read more
-
The Hacker News
VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances
A China-nexus cyber espionage group has been observed deploying a BSD variant of a known backdoor called BRICKSTORM, as well as two other malware families codenamed PLENET (aka GRIMBOLT) and AGENTPSD ... Read more
-
TheCyberThrone
TheCyberThrone CyberSecurity Newsletter Top 5 Articles – May 2026
June 7, 2026Welcome to TheCyberThrone cybersecurity month in review will be posted covering the important security happenings. This review is for the month ending May 2026.Subscribers favorite #1PyTor ... Read more
-
The Hacker News
CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity security flaw impacting SolarWinds Serv-U multi-protocol file server software to its Known Exploited Vulnera ... Read more
The following table lists the changes that have been made to the
CVE-2026-45659 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Translated by [email protected]
Jul. 23, 2026
Action Type Old Value New Value Added Translation Title: varias versiones de Microsoft SharePoint Server, Description: La deserialización de datos no confiables en Microsoft Office SharePoint permite a un atacante autorizado ejecutar código a través de una red. -
Modified Analysis by [email protected]
Jul. 02, 2026
Action Type Old Value New Value Added Reference Type CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-45659 Types: US Government Resource -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jul. 02, 2026
Action Type Old Value New Value Changed SSVC {'id': 'CVE-2026-45659', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'active'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-07-01T19:54:19.019003Z'} {'id': 'CVE-2026-45659', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'active'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-05-26T00:00:00+00:00'} -
CVE CISA KEV Update by 9119a7d8-5eab-497f-8521-727c672e3725
Jul. 01, 2026
Action Type Old Value New Value Added Date Added 2026-07-01 Added Due Date 2026-07-01 Added Required Action 2026-07-01 Added Vulnerability Name 2026-07-01 -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jul. 01, 2026
Action Type Old Value New Value Added Reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-45659 Changed SSVC {'id': 'CVE-2026-45659', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-05-26T00:00:00+00:00'} {'id': 'CVE-2026-45659', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'active'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-07-01T19:54:19.019003Z'} -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jun. 17, 2026
Action Type Old Value New Value Added SSVC {'id': 'CVE-2026-45659', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-05-26T00:00:00+00:00'} -
CVE Modified by [email protected]
Jun. 17, 2026
Action Type Old Value New Value Added Affected [{'vendor': 'Microsoft', 'product': 'Microsoft SharePoint Enterprise Server 2016', 'versions': [{'status': 'affected', 'version': '16.0.0', 'lessThan': '16.0.5552.1002', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Microsoft SharePoint Server 2019', 'versions': [{'status': 'affected', 'version': '16.0.0', 'lessThan': '16.0.10417.20128', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Microsoft SharePoint Server Subscription Edition', 'versions': [{'status': 'affected', 'version': '16.0.0', 'lessThan': '16.0.19725.20280', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}] -
Initial Analysis by [email protected]
May. 27, 2026
Action Type Old Value New Value Added CPE Configuration OR *cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* *cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:* *cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:* versions up to (excluding) 16.0.19725.20280 Added Reference Type Microsoft Corporation: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659 Types: Vendor Advisory -
New CVE Received by [email protected]
May. 22, 2026
Action Type Old Value New Value Added Description Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Added CWE CWE-502 Added Reference https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659