All stories

Attackers exploit Microsoft SharePoint deserialization flaw to achieve remote code execution

Attackers are actively exploiting a high-severity deserialization flaw in Microsoft SharePoint to execute code remotely. This vulnerability requires only low-level authenticated access and can be triggered over a network without user interaction. Patch your SharePoint servers immediately to mitigate the risk.

Summary

CISA has added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog following reports of active exploitation. The flaw exists in how Microsoft SharePoint handles untrusted data during deserialization, allowing an attacker with minimal permissions to execute arbitrary code on unpatched servers.

While Microsoft released security updates for several SharePoint versions on May 21, the vulnerability was reportedly omitted from the initial May 2026 Security Updates. This delay left many systems exposed while attackers began targeting the flaw. Shadowserver is currently tracking over 10,000 SharePoint servers exposed to the internet, though it is not yet known how many of these instances remain unpatched against this specific exploit.

Technical details

The vulnerability (CVE-2026-45659) stems from a deserialization of untrusted data weakness (CWE-502). This allows an authenticated attacker to send malicious payloads that, when processed by the SharePoint component, grant remote code execution.

Exploitation is considered low complexity. An attacker does not need significant prior knowledge or administrative privileges to succeed. According to Microsoft, any authenticated user with at least Site Member permissions (PR:L) can trigger the vulnerability. Because the attack vector is network-based, it can be executed from the internet against vulnerable components.

Affected products and fixed versions

The following SharePoint versions are affected by this flaw. Users should verify their current build numbers against the fixed versions listed below.

Product Vulnerable Version (Less Than)
Microsoft SharePoint Enterprise Server 2016 16.0.5552.1002
Microsoft SharePoint Server 2019 16.0.10417.20128
Microsoft SharePoint Server Subscription Edition 16.0.19725.20280

Why this matters for defenders

This vulnerability represents a significant risk to enterprise environments because it allows attackers to move from low-privilege access to full code execution. CISA has noted that this type of flaw is a frequent attack vector for malicious actors. Since 2021, 11 Microsoft SharePoint vulnerabilities have been abused in the wild, with seven of those linked to ransomware campaigns.

For federal agencies, CISA has issued an urgent directive via BOD 26-04. Under this directive, federal civilian executive branch agencies must secure their servers by July 4, 2026. This mandate prioritizes vulnerabilities that are actively exploited and can grant attackers control over a targeted device.

Defender guidance

Immediate patching is the primary defense against this exploit. Ensure all SharePoint instances-including those exposed to the internet-are updated to the latest builds provided by Microsoft.

If you cannot apply patches immediately, evaluate your asset's internet exposure. For cloud services, follow applicable BOD 26-04 guidance or discontinue use of the product if mitigations are unavailable. Stakeholders should prioritize patching based on whether the SharePoint server is publicly accessible and the potential impact of successful exploitation.

Sources

  1. https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-rce-flaw-now-actively-exploited/
  2. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-45659
  3. https://nvd.nist.gov/vuln/detail/CVE-2026-45659
  4. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -