Known Exploited Vulnerability
8.8
HIGH CVSS 3.1
CVE-2026-45659
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability - [Actively Exploited]
Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

INFO

Published Date :

May 22, 2026, 11:16 p.m.

Last Modified :

July 23, 2026, 11:10 a.m.

Remotely Exploit :

No
CISA Notification
CISA KEV (Known Exploited Vulnerabilities)

For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.

Description :

Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.

Required Action :

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Known Ransomware Campaign Use:

Unknown

Notes :

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-45659

Affected Products

The following products are affected by CVE-2026-45659 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Microsoft sharepoint_server
2 Microsoft sharepoint_enterprise_server_2016
3 Microsoft sharepoint_server_2016
4 Microsoft sharepoint_server_2019
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 134c704f-9b21-4f2e-91b3-4a467353bcc0
CVSS 3.1 HIGH f38d906d-7342-40ea-92c1-6c4a2c6478c8
CVSS 3.1 HIGH [email protected]
Public PoC/Exploit Available at Github

CVE-2026-45659 has a 14 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2026-45659.

URL Resource
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659 Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-45659 US Government Resource
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-45659 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-45659 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

End-to-end technical analysis and reproduction notes for high-impact CVEs (e.g., pre-auth RCEs, sandbox escapes, and privilege escalations).

Updated: 1 day, 20 hours ago
0 stars 0 fork 0 watcher
Born at : July 21, 2026, 3:46 a.m. This repo has been linked 13 different CVEs too.

Cybersecurity research notes on threat intelligence, vulnerabilities, incident response, detection ideas, and SOC analyst learning.

cve cybersecurity detection-engineering incident-response malware-analysis mitre-attack security-operations security-research siem soc threat-intelligence vulnerability-management

Updated: 2 weeks ago
0 stars 0 fork 0 watcher
Born at : July 9, 2026, 3:06 p.m. This repo has been linked 3 different CVEs too.

Professional vulnerability assessment report for SharePoint deserialization risk, including executive summary, technical impact, remediation, and mitigation strategy.

cve-analysis remediation root-cause-analysis security-research technical-writing vulnerability-research

Python

Updated: 6 days, 6 hours ago
2 stars 0 fork 0 watcher
Born at : July 7, 2026, 11:52 p.m. This repo has been linked 1 different CVEs too.

MCP server for Purify security-intelligence feeds (CISA KEV / EPSS) with per-record provenance

cisa-kev claude cve epss mcp mcp-server security-intelligence

Go

Updated: 2 weeks, 4 days ago
0 stars 0 fork 0 watcher
Born at : July 5, 2026, 3:02 p.m. This repo has been linked 1 different CVEs too.

None

JavaScript Makefile HTML TypeScript Shell CSS

Updated: 2 weeks, 4 days ago
0 stars 0 fork 0 watcher
Born at : July 5, 2026, 2:11 p.m. This repo has been linked 1 different CVEs too.

주요 CVE 분석

Updated: 4 days, 4 hours ago
0 stars 0 fork 0 watcher
Born at : July 3, 2026, 5:27 a.m. This repo has been linked 154 different CVEs too.

None

Updated: 1 month, 2 weeks ago
0 stars 0 fork 0 watcher
Born at : June 9, 2026, 11:16 a.m. This repo has been linked 1 different CVEs too.

None

Updated: 1 month, 3 weeks ago
0 stars 0 fork 0 watcher
Born at : June 1, 2026, 7:43 a.m. This repo has been linked 1 different CVEs too.

None

Python

Updated: 6 days, 14 hours ago
0 stars 0 fork 0 watcher
Born at : May 27, 2026, 4:28 p.m. This repo has been linked 7 different CVEs too.

CVE-2026-45659

Python

Updated: 1 week, 3 days ago
0 stars 0 fork 0 watcher
Born at : May 27, 2026, 1:25 a.m. This repo has been linked 1 different CVEs too.

Audit CVE impact, patch status, remediation progress, and verification results across systems.

Makefile Go

Updated: 6 days ago
3 stars 2 fork 2 watcher
Born at : May 16, 2026, 2:19 a.m. This repo has been linked 61 different CVEs too.

An operational threat hunting and detection suite. Maps network and host log queries directly to the MITRE ATT&CK framework, featuring an evidence-driven attribution engine that dynamically correlates indicators to state-sponsored threat actors.

HTML CSS JavaScript

Updated: 1 week, 1 day ago
0 stars 0 fork 0 watcher
Born at : May 1, 2026, 12:35 p.m. This repo has been linked 5 different CVEs too.

The difference between exploitation prediction and detection is akin to the difference between detecting a missile launch or a detonation. Every avoided exploitation cycle saves hundreds of hours of engineering and infosec time.

Jupyter Notebook Python PowerShell

Updated: 4 days, 12 hours ago
14 stars 2 fork 2 watcher
Born at : Jan. 4, 2025, 1:44 a.m. This repo has been linked 277 different CVEs too.

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

security cve exploit poc vulnerability

Updated: 4 days, 9 hours ago
7922 stars 1275 fork 1275 watcher
Born at : Dec. 8, 2019, 1:03 p.m. This repo has been linked 646 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-45659 vulnerability anywhere in the article.

  • The Hacker News
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 ... Read more

Published Date: Jul 21, 2026 (2 days, 13 hours ago)
  • security.nl
Microsoft meldt alsnog actief misbruik van kritiek SharePoint-lek

Een kritieke kwetsbaarheid in Microsoft SharePoint waardoor aanvallers SharePoint-servers op afstand kunnen overnemen is toch wel actief bij aanvallen misbruikt voordat een beveiligingsupdate beschikb ... Read more

Published Date: Jul 17, 2026 (6 days, 20 hours ago)
  • The Hacker News
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) cata ... Read more

Published Date: Jul 17, 2026 (6 days, 21 hours ago)
  • The Hacker News
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described as a Windows User Profile Service arbitrary hive ... Read more

Published Date: Jul 15, 2026 (1 week, 1 day ago)
  • security.nl
Microsoft SharePoint-servers aangevallen, VS roept op tot extra beveiliging

Aanvallers maken actief misbruik van verschillende kwetsbaarheden voor het aanvallen van Microsoft SharePoint-servers, zo waarschuwt het Amerikaanse cyberagentschap CISA. Dat roept organisaties op om ... Read more

Published Date: Jul 15, 2026 (1 week, 1 day ago)
  • TheCyberThrone
Adobe ColdFusion CVE-2026-48282: Under Active Exploitation

Executive SummaryAdobe has released an emergency security update for CVE-2026-48282, a critical vulnerability affecting Adobe ColdFusion. With a CVSS v3.1 score of 10.0, this vulnerability represents ... Read more

Published Date: Jul 07, 2026 (2 weeks, 3 days ago)
  • TheCyberThrone
JadePuffer: The Dawn of Agentic AI Ransomware

When Artificial Intelligence Stops Assisting Attackers and Starts Becoming the AttackerCybersecurity has long anticipated the day when Artificial Intelligence would transition from being a supporting ... Read more

Published Date: Jul 06, 2026 (2 weeks, 3 days ago)
  • TheCyberThrone
Citrix Fixes 6 Vulnerabilities in NetScaler

July 3, 2026Citrix has released security updates for its widely deployed NetScaler ADC and NetScaler Gateway, patching six vulnerabilities that could expose organizations to arbitrary file reads, memo ... Read more

Published Date: Jul 03, 2026 (2 weeks, 6 days ago)
  • TheCyberThrone
CISA Adds CVE-2026-45659 SharePoint Vulnerability to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (Cybersecurity and Infrastructure Security Agency) has added a critical Microsoft SharePoint vulnerability to its Known Exploited Vulnerabilit ... Read more

Published Date: Jul 02, 2026 (3 weeks ago)
  • security.nl
Microsoft SharePoint-servers actief aangevallen via recent beveiligingslek

Een kwetsbaarheid in Microsoft SharePoint waardoor remote code execution (RCE) mogelijk is wordt actief misbruikt bij aanvallen, zo waarschuwt het Amerikaanse cyberagentschap CISA. Microsoft kwam tijd ... Read more

Published Date: Jul 02, 2026 (3 weeks ago)
  • The Hacker News
SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, cit ... Read more

Published Date: Jul 02, 2026 (3 weeks ago)
  • The Hacker News
WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine

Two Russia-aligned cyber attack campaigns have continued to exploit a security flaw in WinRAR to target Ukrainian organisations, almost a year after patches for the vulnerability were released. The ac ... Read more

Published Date: Jun 09, 2026 (1 month, 2 weeks ago)
  • The Hacker News
Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models

University of Toronto researchers have built and tested a proof-of-concept AI-driven computer worm that uses a locally hosted open-weight large language model to reason its way through a network, gene ... Read more

Published Date: Jun 09, 2026 (1 month, 2 weeks ago)
  • The Hacker News
Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now

Google has released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-11645 (CVSS ... Read more

Published Date: Jun 09, 2026 (1 month, 2 weeks ago)
  • The Hacker News
LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity flaw impacting BerriAI LiteLLM to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of ... Read more

Published Date: Jun 09, 2026 (1 month, 2 weeks ago)
  • The Hacker News
One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public

Security researchers have published a detailed, working exploit for a Linux kernel use-after-free that lets an unprivileged local user escalate to root and break out of a container. The flaw, CVE-2026 ... Read more

Published Date: Jun 08, 2026 (1 month, 2 weeks ago)
  • The Hacker News
Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups

Check Point has warned of active exploitation of a critical vulnerability impacting Remote Access VPN and Mobile Access deployments that are configured to use the deprecated IKEv1 key exchange protoco ... Read more

Published Date: Jun 08, 2026 (1 month, 2 weeks ago)
  • The Hacker News
VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances

A China-nexus cyber espionage group has been observed deploying a BSD variant of a known backdoor called BRICKSTORM, as well as two other malware families codenamed PLENET (aka GRIMBOLT) and AGENTPSD ... Read more

Published Date: Jun 08, 2026 (1 month, 2 weeks ago)
  • TheCyberThrone
TheCyberThrone CyberSecurity Newsletter Top 5 Articles – May 2026

June 7, 2026Welcome to TheCyberThrone cybersecurity month in review will be posted covering the important security happenings. This review is for the month ending May 2026.Subscribers favorite #1PyTor ... Read more

Published Date: Jun 07, 2026 (1 month, 2 weeks ago)
  • The Hacker News
CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity security flaw impacting SolarWinds Serv-U multi-protocol file server software to its Known Exploited Vulnera ... Read more

Published Date: Jun 06, 2026 (1 month, 2 weeks ago)

The following table lists the changes that have been made to the CVE-2026-45659 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Translated by [email protected]

    Jul. 23, 2026

    Action Type Old Value New Value
    Added Translation Title: varias versiones de Microsoft SharePoint Server, Description: La deserialización de datos no confiables en Microsoft Office SharePoint permite a un atacante autorizado ejecutar código a través de una red.
  • Modified Analysis by [email protected]

    Jul. 02, 2026

    Action Type Old Value New Value
    Added Reference Type CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-45659 Types: US Government Resource
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jul. 02, 2026

    Action Type Old Value New Value
    Changed SSVC {'id': 'CVE-2026-45659', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'active'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-07-01T19:54:19.019003Z'} {'id': 'CVE-2026-45659', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'active'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-05-26T00:00:00+00:00'}
  • CVE CISA KEV Update by 9119a7d8-5eab-497f-8521-727c672e3725

    Jul. 01, 2026

    Action Type Old Value New Value
    Added Date Added 2026-07-01
    Added Due Date 2026-07-01
    Added Required Action 2026-07-01
    Added Vulnerability Name 2026-07-01
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jul. 01, 2026

    Action Type Old Value New Value
    Added Reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-45659
    Changed SSVC {'id': 'CVE-2026-45659', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-05-26T00:00:00+00:00'} {'id': 'CVE-2026-45659', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'active'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-07-01T19:54:19.019003Z'}
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jun. 17, 2026

    Action Type Old Value New Value
    Added SSVC {'id': 'CVE-2026-45659', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-05-26T00:00:00+00:00'}
  • CVE Modified by [email protected]

    Jun. 17, 2026

    Action Type Old Value New Value
    Added Affected [{'vendor': 'Microsoft', 'product': 'Microsoft SharePoint Enterprise Server 2016', 'versions': [{'status': 'affected', 'version': '16.0.0', 'lessThan': '16.0.5552.1002', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Microsoft SharePoint Server 2019', 'versions': [{'status': 'affected', 'version': '16.0.0', 'lessThan': '16.0.10417.20128', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Microsoft SharePoint Server Subscription Edition', 'versions': [{'status': 'affected', 'version': '16.0.0', 'lessThan': '16.0.19725.20280', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}]
  • Initial Analysis by [email protected]

    May. 27, 2026

    Action Type Old Value New Value
    Added CPE Configuration OR *cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* *cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:* *cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:* versions up to (excluding) 16.0.19725.20280
    Added Reference Type Microsoft Corporation: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659 Types: Vendor Advisory
  • New CVE Received by [email protected]

    May. 22, 2026

    Action Type Old Value New Value
    Added Description Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
    Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-502
    Added Reference https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.