AllCyberNews

CVE-2026-45659

Microsoft SharePoint Remote Code Execution Vulnerability

CVSS 8.8 high · Microsoft Microsoft SharePoint Enterprise Server 2016 · published 2026-05-22

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Coverage 2 sources

  1. 2026-05-26 Help Net Security high High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659)

    Microsoft patches high-severity RCE bug in SharePoint (CVE-2026-45659)

  2. 2026-07-01 CISA Cybersecurity Advisories high CISA Adds One Known Exploited Vulnerability to Catalog

    CISA added CVE-2026-45659, a Microsoft SharePoint Server vulnerability, to its Known Exploited Vulnerabilities Catalog.

  3. 2026-07-14 CISA Cybersecurity Advisories high CISA Urges SharePoint Hardening After New Exploitations

    CISA warns of active exploitation of SharePoint vulnerabilities allowing unauthorized access.

Mentioned with

CVE-2026-32201 CVE-2026-56164

Also covered