www.darkreading.com 5/26/2026, 8:56:37 PM · external

Microsoft patches critical SharePoint RCE flaw CVE-2026-45659

Microsoft patches critical SharePoint RCE flaw CVE-2026-45659
CyberSIXT Evidence Panel
Primary Source msrc.microsoft.com
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

MICROSOFT has released an out-of-band patch to address a critical remote code execution vulnerability in SharePoint Server (CVE-2026-45659). This flaw allows authenticated attackers to remotely execute code without elevated privileges, assigning it a high severity rating of 8.8 on the CVSS scale. Although no public exploit code is currently reported and there are no indications of active exploitation, the patch is recommended for immediate deployment due to SharePoint's status as a frequent target for cyberattacks.

The vulnerability arises from deserialization of untrusted data, potentially leading to significant impacts on system confidentiality, integrity, and availability. Organizations using SharePoint are advised to quickly apply the patch to safeguard their environments.

View Primary Source Via www.darkreading.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline