🚨 CVE-2026-45659 — SharePoint Server RCE (CVSS 8.8)
Confirmed actively exploited. Added to CISA's Known Exploited Vulnerabilities catalog on July 1.
Microsoft patched this quietly in May — the security bulletin wasn't published until three weeks later. Root cause: unsafe deserialization. An attacker only needs Site Member access, not admin.
Affected: SharePoint Server Subscription Edition, 2019, and Enterprise 2016.
Full breakdown + patch guidance:
https://exploitgrid.net/blogs/cve-2026-45659-sharepoint-rce-active-exploitation
#CVE #SharePoint #CISAKEV #VulnerabilityManagement
Confirmed actively exploited. Added to CISA's Known Exploited Vulnerabilities catalog on July 1.
Microsoft patched this quietly in May — the security bulletin wasn't published until three weeks later. Root cause: unsafe deserialization. An attacker only needs Site Member access, not admin.
Affected: SharePoint Server Subscription Edition, 2019, and Enterprise 2016.
Full breakdown + patch guidance:
https://exploitgrid.net/blogs/cve-2026-45659-sharepoint-rce-active-exploitation
#CVE #SharePoint #CISAKEV #VulnerabilityManagement
