CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Microsoft SharePoint Server CWE-502 deserialization RCE, authenticated Site Member (PR:L); CISA KEV since 2026-07-01 and flagged for known ransomware campaign use as of catalog version 2026.08.11

cve · CVE-2026-45659

Coverage
1
first 2026-05-27 → last 2026-08-16
Latest activity
2026-08-13
CVE-2026-45659, Microsoft SharePoint Server: authenticated deserialization RCE, now KEV-listed
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, technology, education · regions: europe, switzerland
Sources cited
4
4 hosts

Action items (1)

Do-now tasks recorded on the entries about CVE-2026-45659, newest first. Check the date before acting on an older one.

  • Apply the May SharePoint update now if you deferred it; CVE-2026-45659 is now KEV-listed as actively exploited despite Microsoft's "Exploitation Less Likely" rating; the fix has shipped since 21 May. Hunt SharePoint/IIS logs for anomalous POST bodies to object-model/API endpoints from Site-Member sessions followed by unexpected w3wp.exe child processes.
    2026-07-02CVE-2026-45659

Defender insights

What each entry about CVE-2026-45659 tells a defender to do, newest first.

2026-07-02HIGHexploitedCVE-2026-45659, Microsoft SharePoint Server: authenticated deserialization RCE, now KEV-listed

Story timeline

  1. 2026-07-02CVE-2026-45659, Microsoft SharePoint Server: authenticated deserialization RCE, now KEV-listed
    trending-vulnerabilities
ATT&CK techniques (2 across 2 tactics)

2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application
  • PersistenceServer Software Component: Web Shell

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-02/cve-2026-45659-microsoft-sharepoint-server-authenticated-des · ATT&CK page ↗

Persistence TA0003

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-07-02/cve-2026-45659-microsoft-sharepoint-server-authenticated-des · ATT&CK page ↗

Entries about Microsoft SharePoint Server CWE-502 deserialization RCE, authenticated Site Member (PR:L); CISA KEV since 2026-07-01 and flagged for known ransomware campaign use as of catalog version 2026.08.11 (1)

2026-07-02 · view entry permalink →

HIGHCVE-2026-45659exploitedupdated

CVE-2026-45659, Microsoft SharePoint Server: authenticated deserialization RCE, now KEV-listed

CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog on 2026-07-01 (CISA KEV feed, 2026-07-01), the operationally significant signal here, because it is the first public confirmation that this deserialization path is under active exploitation. The flaw (CWE-502, deserialization of untrusted data, CVSS 8.8) lets an attacker holding a minimum of Site Member permissions execute code on the SharePoint Server backend with no further user interaction (Microsoft MSRC). It affects SharePoint Server Subscription Edition, 2019 and Enterprise Server 2016, and Microsoft shipped the fix on 2026-05-21 (Microsoft MSRC); the CVE having initially been omitted from the May 2026 Security Updates before publication, per Help Net Security's coverage (Help Net Security, 2026-05-26). Notably, Microsoft's own advisory still rates the CVE "Exploitation Less Likely"; a contradiction defenders should resolve in favour of the exploitation evidence. On-prem operators who deferred the May update because of that low rating should apply it now; hunt SharePoint/IIS logs for anomalous POST bodies to the SharePoint object-model / API endpoints from low-privileged Site-Member sessions followed by unexpected w3wp.exe child-process spawns (T1190, with T1505.003-style web-shell follow-on typical of prior SharePoint deserialization waves).

CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog on 2026-07-01 (CISA KEV feed, 2026-07-01), the operationally significant signal here, because it is the first public confirmation that this deserialization path is under active exploitation.

ctipilot v2 brief (migrated)

On Tuesday, CISA also confirmed that a high-severity Microsoft SharePoint remote code execution vulnerability (CVE-2026-45659), flagged as actively exploited since early July, is now also being exploited by ransomware gangs.

BleepingComputer 2026-08-12

Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.

CISA Known Exploited Vulnerabilities catalog
Updaterun 2026-08-13T0412Z-intelaffected_productscvesevidenceregionssectorssourcestagstechniquesbody

The original entry recorded CISA's 1 July catalogue addition for CVE-2026-45659 as the first public confirmation that this SharePoint deserialization path was being exploited, against a Microsoft advisory that still rated it "Exploitation Less Likely". The catalogue entry has since gained a second flag.

Queried directly this run, the Known Exploited Vulnerabilities catalog at version 2026.08.11 records CVE-2026-45659 with its ransomware-campaign-use field set to "Known" (CISA KEV catalog, 2026-08-11). That the value changed on 11 August, rather than having been present since the July addition, is reported separately: CISA "confirmed that a high-severity Microsoft SharePoint remote code execution vulnerability (CVE-2026-45659), flagged as actively exploited since early July, is now also being exploited by ransomware gangs" (BleepingComputer, 2026-08-12). The same reporting notes that of the fourteen SharePoint vulnerabilities the agency has flagged as actively exploited since November 2021, eight have also been exploited in ransomware attacks.

The flaw itself is unchanged from the original coverage: deserialization of untrusted data reachable by an attacker holding at least Site Member permissions, CVSS 8.8, patched by Microsoft on 2026-05-21. No source names the operation responsible, its victims, or how the required authenticated access is obtained in these campaigns, and none is asserted here.

vulnerability02 Jul 04:55Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • bleepingcomputer.com1 (25%)
  • cisa.gov1 (25%)
  • helpnetsecurity.com1 (25%)
  • msrc.microsoft.com1 (25%)