CISA added a high-severity Microsoft SharePoint Server vulnerability to its Known Exploited Vulnerabilities catalog on Wednesday. The reason: someone is actively exploiting it.
The bug is CVE-2026-45659, a remote code execution flaw with a CVSS score of 8.8. It works through deserialization of untrusted data — basically, the software does not properly check what it is unpacking, and an attacker can slip malicious code in.
Microsoft patched this in May 2026. The fix covers SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016.
Here is what makes it nasty. You do not need admin rights. Any authenticated user with Site Member permissions can trigger it over a network. That is a low bar.
CISA gave federal agencies until July 4 to apply the fix. If you run SharePoint on-premises, that deadline applies to you too, even if you are not a government agency.
Separately, Microsoft also revealed that two unrelated attacker groups were operating inside the same network during a ransomware investigation. One group — Storm-2603 — is known for deploying Warlock ransomware, often by exploiting old SharePoint vulnerabilities. They have been at it since mid-2025.
The other group used tools like Velociraptor (a legitimate DFIR tool) to blend in, set up multiple remote access channels through Cloudflare tunneling and Zoho Assist, and abused a vulnerable driver called NSecKrnl.sys to disable endpoint security.
If you have SharePoint exposed to the internet, patch CVE-2026-45659. Today.
