ctipilot.ch

Microsoft SharePoint Server CWE-502 deserialization RCE — authenticated Site Member (PR:L); CISA KEV since 2026-07-01 and flagged for known ransomware campaign use as of catalog version 2026.08.11

cve · CVE-2026-45659

Coverage timeline
2
first 2026-05-27 → last 2026-08-16
Peak priority
high
1 high · 1 notable
Sources cited
4
4 hosts
Sections touched
2
trending-vulnerabilities, updates
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
2
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques
Affected products
Microsoft SharePoint Enterprise Server 2016Microsoft SharePoint Server 2019Microsoft SharePoint Server Subscription Edition

ATT&CK techniques

2 techniques observed across 2 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×2

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-13/cve-2026-45659-sharepoint-kev-ransomware-use-flagged · 2026-07-02/cve-2026-45659-microsoft-sharepoint-server-authenticated-des · ATT&CK page ↗

Persistence TA0003

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-07-02/cve-2026-45659-microsoft-sharepoint-server-authenticated-des · ATT&CK page ↗

Story timeline

  1. 2026-08-13UPDATE — CISA now records the already-exploited SharePoint deserialization flaw CVE-2026-45659 as used in ransomware campaigns, changing what an unpatched farm risks
    updatesA SharePoint remote-code-execution flaw exploited since July is now flagged for known ransomware campaign use in the federal catalogue
  2. 2026-07-02CVE-2026-45659 — Microsoft SharePoint Server: authenticated deserialization RCE, now KEV-listed
    trending-vulnerabilities

Where this entity is cited

  • trending-vulnerabilities1
  • updates1

Source distribution

  • bleepingcomputer.com1 (25%)
  • cisa.gov1 (25%)
  • helpnetsecurity.com1 (25%)
  • msrc.microsoft.com1 (25%)

explore in graph

Entries about Microsoft SharePoint Server CWE-502 deserialization RCE — authenticated Site Member (PR:L); CISA KEV since 2026-07-01 and flagged for known ransomware campaign use as of catalog version 2026.08.11 (2)

2026-08-13 · view entry permalink →

NOTABLECVE-2026-45659exploitedupdateNATOA1

UPDATE — CISA now records the already-exploited SharePoint deserialization flaw CVE-2026-45659 as used in ransomware campaigns, changing what an unpatched farm risks

UPDATE · originally covered CVE-2026-45659 — Microsoft SharePoint Server: authenticated deserialization RCE, now KEV-listed (2026-07-02)

the original entry recorded CISA's 1 July catalogue addition for CVE-2026-45659 as the first public confirmation that this SharePoint deserialization path was being exploited, against a Microsoft advisory that still rated it "Exploitation Less Likely". The catalogue entry has since gained a second flag.

Queried directly this run, the Known Exploited Vulnerabilities catalog at version 2026.08.11 records CVE-2026-45659 with its ransomware-campaign-use field set to "Known" (CISA KEV catalog, 2026-08-11). That the value changed on 11 August, rather than having been present since the July addition, is reported separately: CISA "confirmed that a high-severity Microsoft SharePoint remote code execution vulnerability (CVE-2026-45659), flagged as actively exploited since early July, is now also being exploited by ransomware gangs" (BleepingComputer, 2026-08-12). The same reporting notes that of the fourteen SharePoint vulnerabilities the agency has flagged as actively exploited since November 2021, eight have also been exploited in ransomware attacks.

The flaw itself is unchanged from the original coverage: deserialization of untrusted data reachable by an attacker holding at least Site Member permissions, CVSS 8.8, patched by Microsoft on 2026-05-21. No source names the operation responsible, its victims, or how the required authenticated access is obtained in these campaigns, and none is asserted here.

On Tuesday, CISA also confirmed that a high-severity Microsoft SharePoint remote code execution vulnerability (CVE-2026-45659), flagged as actively exploited since early July, is now also being exploited by ransomware gangs.

BleepingComputer 2026-08-12

Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.

CISA Known Exploited Vulnerabilities catalog 2026-08-11
vulnerability13 Aug 05:02Zmulti-sourceOpen finding ↗

2026-07-02 · view entry permalink →

HIGHCVE-2026-45659exploited

CVE-2026-45659 — Microsoft SharePoint Server: authenticated deserialization RCE, now KEV-listed

CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog on 2026-07-01 (CISA KEV feed, 2026-07-01) — the operationally significant signal here, because it is the first public confirmation that this deserialization path is under active exploitation. The flaw (CWE-502, deserialization of untrusted data, CVSS 8.8) lets an attacker holding a minimum of Site Member permissions execute code on the SharePoint Server backend with no further user interaction (Microsoft MSRC). It affects SharePoint Server Subscription Edition, 2019 and Enterprise Server 2016, and Microsoft shipped the fix on 2026-05-21 (Microsoft MSRC) — the CVE having initially been omitted from the May 2026 Security Updates before publication, per Help Net Security's coverage (Help Net Security, 2026-05-26). Notably, Microsoft's own advisory still rates the CVE "Exploitation Less Likely" — a contradiction defenders should resolve in favour of the exploitation evidence. On-prem operators who deferred the May update because of that low rating should apply it now; hunt SharePoint/IIS logs for anomalous POST bodies to the SharePoint object-model / API endpoints from low-privileged Site-Member sessions followed by unexpected w3wp.exe child-process spawns (T1190, with T1505.003-style web-shell follow-on typical of prior SharePoint deserialization waves).

CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog on 2026-07-01 (CISA KEV feed, 2026-07-01) — the operationally significant signal here, because it is the first public confirmation that this deserialization path is under active exploitation.

ctipilot v2 brief (migrated)
vulnerability02 Jul 04:55Zmulti-sourceOpen finding ↗