Remote Code Execution Vulnerability in Microsoft SharePoint Under Active Exploitation by Attackers
Attackers are actively exploiting a high-severity deserialization vulnerability in Microsoft SharePoint. This flaw allows authorized users to execute code over a network, potentially granting full control of the server. Patch your SharePoint Enterprise Server 2016 instances immediately. 馃毃
Summary
CISA has added CVE-2026-45659 to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation in the wild. The vulnerability exists in Microsoft SharePoint Enterprise Server 2016 and stems from how the application handles untrusted data during deserialization processes.
The flaw carries a CVSS score of 8.8, reflecting its high impact on confidentiality, integrity, and availability. Because the vulnerability can be triggered over a network by an authorized user, it presents a significant risk to organizations running unpatched SharePoint environments.
Technical details
The core issue lies in the deserialization of untrusted data within Microsoft Office SharePoint. When the application processes specially crafted input, an attacker can trigger unauthorized code execution.
This type of vulnerability is a frequent target for malicious actors because it often allows for a transition from standard user access to full system control. In this specific case, the attack vector requires the actor to have authorized access to the environment, but once triggered, the impact extends across the network.
Exploitation status
CISA confirmed on July 1, 2026, that this vulnerability is currently being exploited in active campaigns. As a result, it has been added to the KEV Catalog to signal its immediate risk to federal and private sector assets.
For Federal Civilian Executive Branch (FCEB) agencies, remediation is mandated under Binding Operational Directive (BOD) 26-04. This directive requires agencies to prioritize the patching of high-risk vulnerabilities found in the KEV catalog, especially those on publicly exposed assets that could lead to total asset control post-exploitation.
Defender guidance
Prioritize the application of security updates for Microsoft SharePoint Enterprise Server 2016. Because this vulnerability is being actively exploited, waiting for a standard patch cycle increases the window of opportunity for attackers.
If you manage SharePoint environments, perform a forensic review of your systems to determine if they were compromised before patches were applied. This follows the guidance established in BOD 26-04 regarding post-exploitation verification.
Focus remediation efforts on any SharePoint instances that are publicly accessible or reside on critical network segments.
