2026-07-02HIGHexploitedCVE-2026-45659, Microsoft SharePoint Server: authenticated deserialization RCE, now KEV-listed
Microsoft SharePoint Server CWE-502 deserialization RCE, authenticated Site Member (PR:L); CISA KEV since 2026-07-01 and flagged for known ransomware campaign use as of catalog version 2026.08.11
cve · CVE-2026-45659
Coverage
1
first 2026-05-27 → last 2026-08-16
Latest activity
2026-08-13
CVE-2026-45659, Microsoft SharePoint Server: authenticated deserialization RCE, now KEV-listed
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, technology, education · regions: europe, switzerland
Sources cited
4
4 hosts
Action items (1)
Do-now tasks recorded on the entries about CVE-2026-45659, newest first. Check the date before acting on an older one.
- Apply the May SharePoint update now if you deferred it; CVE-2026-45659 is now KEV-listed as actively exploited despite Microsoft's "Exploitation Less Likely" rating; the fix has shipped since 21 May. Hunt SharePoint/IIS logs for anomalous POST bodies to object-model/API endpoints from Site-Member sessions followed by unexpected2026-07-02CVE-2026-45659
w3wp.exechild processes.
Defender insights
What each entry about CVE-2026-45659 tells a defender to do, newest first.
Story timeline
- 2026-07-02CVE-2026-45659, Microsoft SharePoint Server: authenticated deserialization RCE, now KEV-listed
Hunting pivots
Affected products
ATT&CK techniques (2 across 2 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- PersistenceServer Software Component: Web Shell
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-02/cve-2026-45659-microsoft-sharepoint-server-authenticated-des · ATT&CK page ↗
Persistence TA0003
T1505.003Server Software Component: Web Shell×1
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Evidence: 2026-07-02/cve-2026-45659-microsoft-sharepoint-server-authenticated-des · ATT&CK page ↗
Entries about Microsoft SharePoint Server CWE-502 deserialization RCE, authenticated Site Member (PR:L); CISA KEV since 2026-07-01 and flagged for known ransomware campaign use as of catalog version 2026.08.11 (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- bleepingcomputer.com1 (25%)
- cisa.gov1 (25%)
- helpnetsecurity.com1 (25%)
- msrc.microsoft.com1 (25%)
External references
All cited sources (4)
- msrc.microsoft.comprimaryMicrosoft MSRChttps://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45659
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/microsoft/hackers-leverage-new-microsoft-sharepoint-exploit-in-attacks/
- cisa.govCISA KEV feedhttps://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- helpnetsecurity.comHelp Net Securityhttps://www.helpnetsecurity.com/2026/05/26/sharepoint-vulnerability-cve-2026-45659/