top of page

Urgent warning: Critical Microsoft SharePoint vulnerability actively exploited

The Microsoft SharePoint storage and collaboration platform is a widely used system across many organizations and enterprises. However, a high-severity security vulnerability has recently been discovered and is being actively exploited by threat actors in the wild. International cybersecurity agencies have urgently issued warnings, demanding that organizations take immediate remediation steps.

Details of the critical Microsoft SharePoint vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently announced that threat actors are actively exploiting a critical vulnerability in Microsoft SharePoint Server. This threat is tracked under CVE-2026-45659, with a high-severity CVSS score of 8.8.

A critical vulnerability in Microsoft SharePoint Server is tracked under CVE-2026-45659 with a CVSS score of 8.8
A critical vulnerability in Microsoft SharePoint Server is tracked under CVE-2026-45659 with a CVSS score of 8.8

Technically, this flaw involves insecure data handling (untrusted data deserialization). The nature of this vulnerability allows authenticated attackers to execute remote arbitrary code on affected SharePoint servers, thereby gaining full control of the system. Although Microsoft released an out-of-band emergency security update to address this flaw in late May, active attacks continue to occur in the wild.

How do attackers easily gain access?

According to warnings from Microsoft, this vulnerability is highly exploitable. Specifically, threat actors do not require deep expertise or prior internal knowledge of the targeted infrastructure to repeatedly launch successful malware attacks against the affected components.

Notably, attackers do not need high-level administrative privileges. They only require a valid account with minimum privileges, such as a Site Member, to successfully trigger the flaw. The system versions reported to be affected by this vulnerability include:

  • SharePoint Server Subscription Edition

  • SharePoint Server 2019

  • SharePoint Server 2016

  • SharePoint Enterprise Server 2016

Urgent action required by cybersecurity agencies

Due to the severity of the situation, CISA has officially added CVE-2026-45659 to its Known Exploited Vulnerabilities (KEV) catalog. Concurrently, the agency has issued a mandate requiring all federal agencies to complete patch deployments within three days, in compliance with Binding Operational Directive (BOD) 26-04.

Currently, CISA has not disclosed specific details regarding the methodologies or targets of the recorded attacks. Prior to this warning, there had been no public reports of this vulnerability being actively exploited in the wild.

CISA has not yet released specific details regarding the methods or targets of the documented attacks
CISA has not yet released specific details regarding the methods or targets of the documented attacks

This is not the first time Microsoft platforms have been targeted by cybercriminals. Earlier in April, Microsoft patched another zero-day vulnerability in SharePoint. In March, CISA also sounded the alarm over a different security flaw within the Microsoft product ecosystem that was being actively exploited in the wild.

Because SharePoint serves as the backbone for data management, intranet operations, and business workflow integration, it remains a prime target for cyberattacks. To secure sensitive information and internal data, all organizations and enterprises are strongly advised to audit their environments and apply the latest security patches from Microsoft as soon as possible.

How can businesses strengthen their cybersecurity defenses?

Amid the rising wave of highly sophisticated high-tech attacks, securing information systems has become a matter of survival for every organization. Partnering with enterprises on their secure digital transformation journey, IPSIP Vietnam delivers a comprehensive security ecosystem, deep-dive monitoring solutions, and rapid incident response services - providing a rock-solid foundation for businesses to accelerate growth.

IPSIP Vietnam's management and monitoring systems have proven their exceptional capabilities by passing rigorous audits to earn prestigious global information security certifications: ISO 27001:2022 and SOC 2 Type II.

IPSIP’s defensive strength is maintained around the clock through a core trio of 24/7 services:

Commitment from IPSIP Vietnam: Instant response, proactive defense, and interception of all unauthorized intrusions to protect the integrity of enterprise digital assets day and night
Commitment from IPSIP Vietnam: Instant response, proactive defense, and interception of all unauthorized intrusions to protect the integrity of enterprise digital assets day and night

Contact IPSIP Vietnam today to receive an exclusive 15% discount on all services for new clients - activate a robust digital shield and optimize your business costs!


Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page