---
schema: 1
kind: vulnerability
title: "CVE-2026-45659 — Microsoft SharePoint Server: authenticated deserialization RCE, now KEV-listed"
headline: "CVE-2026-45659 — Microsoft SharePoint Server: authenticated deserialization RCE, now KEV-listed"
summary: >
  CISA flags a SharePoint RCE Microsoft downplayed. CISA added CVE-2026-45659 (SharePoint Server
  deserialization-of-untrusted-data RCE, CVSS 8.8, Site-Member-authenticated) to its Known
  Exploited Vulnerabilities catalog on 1 July — the first public confirmation of active
  exploitation for a bug Microsoft's own advisory still rates "Exploitation Less Likely" and
  quietly patched on 21 May (Microsoft MSRC). On-prem SharePoint operators who deferred the May
  fix should treat it as live.
discovered_at: "2026-07-02T04:55:19Z"
updated_at: "2026-08-13T05:02:00Z"
event_date: 2026-07-01
run_id: 2026-07-02-6551f8c2
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - actively-exploited
  - cisa-kev
  - patch-available
  - ransomware
regions:
  - global
  - europe
  - switzerland
sectors:
  - public-sector
  - technology
  - education
  - healthcare
entities: []
techniques:
  - T1190
affected_products:
  - Microsoft SharePoint Server Subscription Edition
  - Microsoft SharePoint Server 2019
  - Microsoft SharePoint Enterprise Server 2016
cves:
  - id: CVE-2026-45659
    cvss: "8.8"
    epss: null
    type: deserialization
    vector: zero-click
    auth: post-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
    affected: >
      SharePoint Server Subscription Edition, 2019 and Enterprise Server 2016 prior to the May 2026
      updates
    fixed: Microsoft security updates of 2026-05-21
sources:
  - url: "https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45659"
    publisher: Microsoft MSRC
    role: primary
  - url: "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json"
    publisher: CISA KEV feed
    role: corroborating
  - url: "https://www.helpnetsecurity.com/2026/05/26/sharepoint-vulnerability-cve-2026-45659/"
    publisher: Help Net Security
    role: corroborating
  - url: "https://www.bleepingcomputer.com/news/microsoft/hackers-leverage-new-microsoft-sharepoint-exploit-in-attacks/"
    publisher: BleepingComputer
    date: 2026-08-12
    role: corroborating
closed_sources: []
evidence:
  - quote: "CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog on 2026-07-01 (CISA KEV feed, 2026-07-01) — the operationally significant signal here, because it is the first public confirmation that this deserialization path is under active exploitation."
    publisher: ctipilot v2 brief (migrated)
  - quote: "On Tuesday, CISA also confirmed that a high-severity Microsoft SharePoint remote code execution vulnerability (CVE-2026-45659), flagged as actively exploited since early July, is now also being exploited by ransomware gangs."
    publisher: BleepingComputer
  - quote: Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
    publisher: CISA Known Exploited Vulnerabilities catalog
verification: multi-source
sourcing_note: "migration: evidence backfilled from v2 brief body (item predates the Evidence footer field)"
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification: null
watchlist_hit: false
actions:
  - "**Apply the May SharePoint update now if you deferred it** — CVE-2026-45659 is now KEV-listed as actively exploited despite Microsoft's \"Exploitation Less Likely\" rating; the fix has shipped since 21 May. Hunt SharePoint/IIS logs for anomalous POST bodies to object-model/API endpoints from Site-Member sessions followed by unexpected `w3wp.exe` child processes."
updates:
  - at: "2026-08-13T05:02:00Z"
    run_id: 2026-08-13T0412Z-intel
    type: update
    summary: >
      CVE-2026-45659, the Site-Member-authenticated deserialization remote-code-execution flaw in
      Microsoft SharePoint Server that CISA added to its Known Exploited Vulnerabilities catalog on
      2026-07-01 and that this pipeline covered the following day, now carries "Known" in the
      catalogue's ransomware-campaign-use field, checked against catalog version 2026.08.11. The
      exploitation itself is not new; what changed is who is using it and to what end. For an
      on-premises SharePoint estate the expected outcome shifts from data access to encryption and
      extortion, which changes recovery planning rather than patch priority — the May 2026 fix has
      been available for nearly three months.
    fields:
      - affected_products
      - cves
      - evidence
      - regions
      - sectors
      - sources
      - tags
      - techniques
      - body
    merged_from: 2026-08-13/cve-2026-45659-sharepoint-kev-ransomware-use-flagged
migrated_from: briefs/2026-07-02.md
---

CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog on 2026-07-01 ([CISA KEV feed, 2026-07-01](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)) — the operationally significant signal here, because it is the first public confirmation that this deserialization path is under active exploitation. The flaw (CWE-502, deserialization of untrusted data, CVSS 8.8) lets an attacker holding a minimum of Site Member permissions execute code on the SharePoint Server backend with no further user interaction ([Microsoft MSRC](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45659)). It affects SharePoint Server Subscription Edition, 2019 and Enterprise Server 2016, and Microsoft shipped the fix on 2026-05-21 ([Microsoft MSRC](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45659)) — the CVE having initially been omitted from the May 2026 Security Updates before publication, per Help Net Security's coverage ([Help Net Security, 2026-05-26](https://www.helpnetsecurity.com/2026/05/26/sharepoint-vulnerability-cve-2026-45659/)). Notably, Microsoft's own advisory still rates the CVE "Exploitation Less Likely" — a contradiction defenders should resolve in favour of the exploitation evidence. On-prem operators who deferred the May update because of that low rating should apply it now; hunt SharePoint/IIS logs for anomalous POST bodies to the SharePoint object-model / API endpoints from low-privileged Site-Member sessions followed by unexpected `w3wp.exe` child-process spawns (T1190, with T1505.003-style web-shell follow-on typical of prior SharePoint deserialization waves).

## Update — 2026-08-13T05:02:00Z

The original entry recorded CISA's 1 July catalogue addition for CVE-2026-45659 as the first public confirmation that this SharePoint deserialization path was being exploited, against a Microsoft advisory that still rated it "Exploitation Less Likely". The catalogue entry has since gained a second flag.

Queried directly this run, the Known Exploited Vulnerabilities catalog at version 2026.08.11 records CVE-2026-45659 with its ransomware-campaign-use field set to "Known" ([CISA KEV catalog, 2026-08-11](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)). That the value changed on 11 August, rather than having been present since the July addition, is reported separately: CISA "confirmed that a high-severity Microsoft SharePoint remote code execution vulnerability (CVE-2026-45659), flagged as actively exploited since early July, is now also being exploited by ransomware gangs" ([BleepingComputer, 2026-08-12](https://www.bleepingcomputer.com/news/microsoft/hackers-leverage-new-microsoft-sharepoint-exploit-in-attacks/)). The same reporting notes that of the fourteen SharePoint vulnerabilities the agency has flagged as actively exploited since November 2021, eight have also been exploited in ransomware attacks.

The flaw itself is unchanged from the original coverage: deserialization of untrusted data reachable by an attacker holding at least Site Member permissions, CVSS 8.8, patched by Microsoft on 2026-05-21. No source names the operation responsible, its victims, or how the required authenticated access is obtained in these campaigns, and none is asserted here.

**Defender takeaway:** this changes the consequence, not the remedy. The fix has existed since May and the exploitation flag since July, so an estate that acted on either is already covered. What the ransomware flag alters is the planning assumption for an estate that did not: the realistic outcome of an unpatched SharePoint farm reachable by a low-privileged account is no longer confined to data disclosure — it now includes encryption of the content the farm holds, which for a public-sector document platform is the operating record rather than an archive. Where the May update genuinely cannot be applied yet, the recovery question is the one to answer this week: whether SharePoint content and configuration backups are restorable independently of the farm itself and of the credentials that reach it. Note also that this is a *distinct* flaw from the pre-authentication token-forgery bypass covered separately in this window, and neither source connects the two; they share only the product.
