Urgent warning: Critical Microsoft SharePoint vulnerability actively exploited
- Thảo Nguyên

- 5 days ago
- 3 min read
The Microsoft SharePoint storage and collaboration platform is a widely used system across many organizations and enterprises. However, a high-severity security vulnerability has recently been discovered and is being actively exploited by threat actors in the wild. International cybersecurity agencies have urgently issued warnings, demanding that organizations take immediate remediation steps.
Details of the critical Microsoft SharePoint vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently announced that threat actors are actively exploiting a critical vulnerability in Microsoft SharePoint Server. This threat is tracked under CVE-2026-45659, with a high-severity CVSS score of 8.8.

Technically, this flaw involves insecure data handling (untrusted data deserialization). The nature of this vulnerability allows authenticated attackers to execute remote arbitrary code on affected SharePoint servers, thereby gaining full control of the system. Although Microsoft released an out-of-band emergency security update to address this flaw in late May, active attacks continue to occur in the wild.
How do attackers easily gain access?
According to warnings from Microsoft, this vulnerability is highly exploitable. Specifically, threat actors do not require deep expertise or prior internal knowledge of the targeted infrastructure to repeatedly launch successful malware attacks against the affected components.
Notably, attackers do not need high-level administrative privileges. They only require a valid account with minimum privileges, such as a Site Member, to successfully trigger the flaw. The system versions reported to be affected by this vulnerability include:
SharePoint Server Subscription Edition
SharePoint Server 2019
SharePoint Server 2016
SharePoint Enterprise Server 2016
Urgent action required by cybersecurity agencies
Due to the severity of the situation, CISA has officially added CVE-2026-45659 to its Known Exploited Vulnerabilities (KEV) catalog. Concurrently, the agency has issued a mandate requiring all federal agencies to complete patch deployments within three days, in compliance with Binding Operational Directive (BOD) 26-04.
Currently, CISA has not disclosed specific details regarding the methodologies or targets of the recorded attacks. Prior to this warning, there had been no public reports of this vulnerability being actively exploited in the wild.

This is not the first time Microsoft platforms have been targeted by cybercriminals. Earlier in April, Microsoft patched another zero-day vulnerability in SharePoint. In March, CISA also sounded the alarm over a different security flaw within the Microsoft product ecosystem that was being actively exploited in the wild.
Because SharePoint serves as the backbone for data management, intranet operations, and business workflow integration, it remains a prime target for cyberattacks. To secure sensitive information and internal data, all organizations and enterprises are strongly advised to audit their environments and apply the latest security patches from Microsoft as soon as possible.
How can businesses strengthen their cybersecurity defenses?
Amid the rising wave of highly sophisticated high-tech attacks, securing information systems has become a matter of survival for every organization. Partnering with enterprises on their secure digital transformation journey, IPSIP Vietnam delivers a comprehensive security ecosystem, deep-dive monitoring solutions, and rapid incident response services - providing a rock-solid foundation for businesses to accelerate growth.
IPSIP Vietnam's management and monitoring systems have proven their exceptional capabilities by passing rigorous audits to earn prestigious global information security certifications: ISO 27001:2022 and SOC 2 Type II.
IPSIP’s defensive strength is maintained around the clock through a core trio of 24/7 services:
SOC 24/7 (Security Operations Center): Proactively hunt and detect threats.
NOC 24/7 (Network Operations Center): Ensure network infrastructure always runs stably and seamlessly.
IT Support/Helpdesk: A technical team in constant combat readiness, poised to handle any request.

Contact IPSIP Vietnam today to receive an exclusive 15% discount on all services for new clients - activate a robust digital shield and optimize your business costs!










Comments