CISA says attackers are exploiting Microsoft SharePoint remote-code-execution flaw CVE-2026-45659

CISA warned that attackers are now actively exploiting a Microsoft SharePoint server flaw that can let a low-privilege user run code on vulnerable systems. The bug, CVE-2026-45659, is a deserialization issue in SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition; Microsoft released fixes on May 21, 2026 after the CVE was omitted from its May security update listing. CISA added it to the Known Exploited Vulnerabilities catalog and ordered U.S. federal agencies to patch by Saturday.
Why it matters: Organizations running on-premises SharePoint, especially internet-exposed servers, should treat this as urgent because attackers can exploit it remotely with only Site Member-level access. Patch immediately, review internet exposure, and check for signs of compromise on SharePoint servers.

Sources

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
info@thehackernews.com (The Hacker News) 2026.07.17 24% relevant
Both stories concern CISA warning about active exploitation of Microsoft SharePoint server remote-code-execution flaws, but this article appears to be about a different CVE (CVE-2026-58644 rather than CVE-2026-45659), so it is related product coverage rather than the same underlying event.
CISA sounds alarm over trio of exploited SharePoint flaws
2026.07.15 93% relevant
This article directly updates the same SharePoint exploitation event by adding that CISA is now warning about a trio of exploited SharePoint flaws, not just CVE-2026-45659. It adds CVE-2026-32201 and CVE-2026-56164 as actively exploited, notes two additional critical SharePoint flaws from July Patch Tuesday (CVE-2026-55040 and CVE-2026-58644) as exploitation-more-likely, and includes CISA's hardening advice around AMSI, IIS key rotation, and restricting external exposure.
CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities
Ionut Arghire 2026.07.15 88% relevant
This article updates the same ongoing SharePoint exploitation story by adding CISA's broader hardening guidance, noting continued concern around CVE-2026-45659, and connecting it to additional exploited SharePoint flaws including CVE-2026-56164 and the earlier zero-day CVE-2026-32201.
CISA warns admins to patch actively exploited SharePoint flaws
Sergiu Gatlan 2026.07.15 95% relevant
This article updates that same SharePoint exploitation wave with CISA's broader warning that three flaws—CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164—are being chained against internet-exposed on-premises SharePoint servers, and adds operational details on post-exploitation activity, patching deadlines, and the additional newly patched CVE-2026-55040 and CVE-2026-58644 as likely next targets.
Microsoft said exploitation was 'less likely' ... but CISA just added SharePoint RCE to KEV list
2026.07.02 98% relevant
This article is a direct update on the same event: CISA adding CVE-2026-45659 to the KEV catalog and confirming active exploitation. It adds context that Microsoft had previously rated exploitation as 'Less Likely,' reiterates that only a valid SharePoint account with Site Member permissions is needed, and notes the federal remediation deadline of July 4 under BOD 26-04.
CISA: Microsoft SharePoint RCE flaw now actively exploited
Sergiu Gatlan 2026.07.02 100% relevant
This article establishes a distinct tracked event by adding the key new development that CVE-2026-45659 in Microsoft SharePoint is now under active exploitation and has entered CISA's KEV process.
CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability
Ionut Arghire 2026.07.02 98% relevant
This article directly matches that event and adds that CISA placed the flaw in the KEV catalog on July 2, 2026, cited active exploitation, and that Microsoft had previously shipped an out-of-band fix in late May for affected SharePoint Server 2016, 2019, Subscription Edition, and SharePoint Enterprise Server 2016.
← Back to all stories