top of page

SharePoint vulnerability CVE-2026-45659 actively exploited, CISA urges immediate patching

CISA has added SharePoint vulnerability CVE-2026-45659 to the Known Exploited Vulnerabilities (KEV) Catalog on July 1, 2026, after confirming active exploitation in the wild. With a CVSS score of 8.8, the vulnerability enables Remote Code Execution (RCE) on Microsoft SharePoint Server when exploited by an authenticated low-privileged user.

The SharePoint vulnerability CVE-2026-45659 has become a high-priority security concern for organizations still operating on-premises Microsoft SharePoint Server. The risk extends beyond remote server compromise, as Microsoft has also revealed incidents involving multiple threat actors operating simultaneously within the same environment.

What is SharePoint Vulnerability CVE-2026-45659?

CVE-2026-45659 is a deserialization of untrusted data vulnerability affecting Microsoft Office SharePoint. According to the National Vulnerability Database (NVD), the flaw allows an authenticated attacker to execute arbitrary code remotely. It carries a CVSS v3.1 score of 8.8 (High Severity), posing significant risks to system confidentiality, integrity, and availability.

One notable aspect of this vulnerability is that administrator privileges are not required. Microsoft, as cited by The Hacker News, states that an attacker only needs an authenticated account with Site Member permissions to exploit the vulnerability over the network.

SharePoint vulnerability CVE-2026-45659 actively exploited
SharePoint vulnerability CVE-2026-45659 actively exploited

Why is it concerning that the SharePoint vulnerability was added to KEV?

The inclusion of CVE-2026-45659 in CISA's Known Exploited Vulnerabilities (KEV) Catalog confirms that the vulnerability has already been exploited in real-world attacks rather than remaining a theoretical risk.

The vulnerability was officially added to the KEV Catalog on July 1, 2026, and U.S. Federal Civilian Executive Branch (FCEB) agencies were instructed to remediate it by July 4, 2026.

For cybersecurity teams, a KEV listing serves as a strong signal that patching should become an immediate priority. Organizations exposing SharePoint services to the internet or supporting a large number of internal users face an elevated risk if updates are delayed.

The danger stems from three combined factors:

  • Remote exploitation

  • Low privilege requirements

  • Direct impact on enterprise collaboration platforms

A compromised low-privileged account may be enough for attackers to establish an initial foothold and launch broader attacks.

Which SharePoint versions are affected?

CVE-2026-45659 affects the following Microsoft products if they have not been updated to secure versions:

  • Microsoft SharePoint Enterprise Server 2016

  • Microsoft SharePoint Server 2019

  • Microsoft SharePoint Server Subscription Edition

According to the NVD, SharePoint Server Subscription Edition versions earlier than 16.0.19725.20280 remain vulnerable.

How can attackers exploit the SharePoint vulnerability?

The documented attack scenario involves an attacker with a legitimate authenticated account sending specially crafted requests that trigger Remote Code Execution (RCE) on the SharePoint server.

The NVD describes the vulnerability as a Deserialization of Untrusted Data flaw that allows authorized attackers to execute code remotely.

For non-technical readers, SharePoint can be thought of as an organization's central collaboration workspace. If an attacker compromises even a low-privileged account, they may not stop at viewing documents. Instead, they can leverage the compromised SharePoint server as a stepping stone to execute code, maintain persistence, and expand deeper into the corporate network.

How can attackers exploit the SharePoint vulnerability?
How can attackers exploit the SharePoint vulnerability?

How does Microsoft's ransomware investigation relate to SharePoint?

Microsoft's latest ransomware investigation demonstrates that modern cyberattacks are often far more complex than they initially appear.

During incident response, Microsoft discovered two unrelated threat groups operating simultaneously within the same compromised environment. Each group maintained its own access methods and persistence techniques, making forensic investigations significantly more challenging.

After establishing access, one threat actor deployed Velociraptor with SYSTEM privileges to map the environment before creating multiple remote access channels, including:

  • Cloudflare Tunnel

  • Zoho Assist

  • SSH

  • Visual Studio Code Remote Tunnel

Microsoft also observed attackers creating local administrator accounts, domain administrator accounts, and abusing vulnerable drivers to weaken endpoint protection before deploying ransomware.

How does Microsoft's ransomware investigation relate to SharePoint?
How does Microsoft's ransomware investigation relate to SharePoint?

Why can multiple threat groups operate inside the same network?

Multiple threat actors may coexist when an organization contains several exploitable weaknesses, ranging from software vulnerabilities and stolen credentials to abused remote administration tools.

Microsoft reported that the second threat actor used entirely different techniques, including:

  • DLL Side-Loading

  • Custom backdoors

These distinct attack methods complicated attribution, forensic analysis, and impact assessment.

The key takeaway is that ransomware should never be treated as an isolated incident. Simply removing ransomware or restoring encrypted servers may leave additional persistence mechanisms, unauthorized administrator accounts, remote access tools, or lateral movement pathways untouched.

What should organizations do immediately?

Organizations running Microsoft SharePoint Server should first determine:

  • Current SharePoint version

  • Patch status

  • User accounts with SharePoint access

Particular attention should be given to Site Member accounts and above, as Microsoft indicates this permission level may be sufficient for exploitation.

Security teams should also review:

  • SharePoint patch history

  • Unusual authentication events

  • Requests targeting sensitive configuration files

  • Newly created administrator accounts

  • Unexpected remote access connections

  • Unauthorized Cloudflare Tunnel, Zoho Assist, or Visual Studio Code Remote Tunnel installations

Protecting your "digital infrastructure" with IPSIP Vietnam

IPSIP Vietnam's management and monitoring platform has successfully passed rigorous independent assessments to achieve internationally recognized ISO/IEC 27001:2022 and SOC 2 Type II certifications. Through its 24/7 Security Operations Center (SOC), 24/7 Network Operations Center (NOC), and dedicated IT Support/Helpdesk teams, IPSIP delivers continuous monitoring, rapid threat detection, and around-the-clock incident response to help organizations defend against cyber threats at any time.

IPSIP Vietnam cybersecurity solutions
IPSIP Vietnam cybersecurity solutions

To strengthen SharePoint security, IPSIP also provides vulnerability assessment services that continuously evaluate SharePoint servers, internal web applications, endpoints, and supporting infrastructure. This enables organizations to identify exploitable weaknesses early, prioritize remediation efforts, and implement a structured risk-based patch management strategy.

For enterprises requiring continuous protection, IPSIP SOC 24/7 delivers real-time log monitoring, anomaly detection, unauthorized administrator account monitoring, suspicious remote access detection, and ransomware threat hunting. By combining advanced monitoring technology with experienced cybersecurity analysts, IPSIP helps organizations overcome the limitations of internal IT teams, providing comprehensive visibility across servers, identities, endpoints, and enterprise networks.

References


Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page