CVE-2026-45659
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Deadline for federal agencies: 2026-07-04.
12 articles across 8 outlets · first covered May 26, 2026 · latest Jul 22, 2026
Tracked incidents
Coverage timeline
-
Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attackswww.securityweek.com · Jul 22, 2026
-
Weekly Threat Intelligence: The July 2026 Breachessecurityonline.info · Jul 6, 2026
-
CISA urges SharePoint patch for CVE-2026-45659 before July 4securityaffairs.com · Jul 2, 2026
-
CISA warns of active SharePoint flaw CVE-2026-45659www.securityweek.com · Jul 2, 2026
-
CISA Flags SharePoint RCE (CVE-2026-45659) for Active Exploitationsocradar.io · Jul 2, 2026
-
SharePoint CVE-2026-45659 added to CISA KEV list amid exploitsthehackernews.com · Jul 2, 2026
-
Attackers exploit SharePoint RCE bug CVE-2026-45659, patch urgedsecurityonline.info · Jul 2, 2026
-
CISA Flags SharePoint CVE-2026-45659 in KEV Catalogwww.cisa.gov · Jul 2, 2026
-
CISA warns of SharePoint deserialization flaw, urges patchcisa.gov · Jul 1, 2026
-
Microsoft SharePoint Has a New RCE Flaw. If You Haven’t Patched Yet, Go Do That.securityaffairs.com · May 27, 2026
-
Microsoft patches critical SharePoint RCE flaw CVE-2026-45659www.darkreading.com · May 26, 2026
-
Microsoft patches critical SharePoint RCE flaw CVE-2026-45659thehackernews.com · May 26, 2026