EXPOSURES › CVE-2026-45659
CVE-2026-45659
HIGH ⌖ ON CISA KEV · EXPLOITEDMicrosoft SharePoint Server allows remote code execution via deserialization of untrusted data.
An authorized attacker can execute arbitrary code over a network by exploiting a deserialization vulnerability in SharePoint Server, enabling lateral movement and data exfiltration. DIB organizations must patch immediately to prevent unauthorized access to sensitive data and maintain FedRAMP/NIST 800-171 compliance. This failure is critical because it allows remote code execution without requiring a zero-day exploit.
Shame score — The vulnerability is actively exploited but not zero-day, and while it allows RCE, it requires an authorized attacker to trigger, reducing immediate embarrassment compared to public-facing exploits.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |