Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-07-04. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Active Exploitation1Disclosure4General1Patch27PoC1
2026-05-28
6
Disclosure1General1Patch4
2026-05-30
3
Patch3
2026-05-31
3
Disclosure1Patch2
2026-06-01
1
Patch1
2026-06-03
1
Disclosure1
2026-06-08
4
Disclosure1Discovery1Patch2
2026-06-09
2
Disclosure1Patch1
2026-06-11
1
Patch1
2026-06-12
1
General1
2026-06-18
2
Disclosure1Patch1
2026-06-28
1
Patch1
2026-07-01
4
Active Exploitation3Disclosure1
2026-07-02
49
Active Exploitation45Disclosure2General1Patch1
2026-07-03
27
Active Exploitation22False Positive1General1Patch3
2026-07-04
6
Active Exploitation5Patch1
2026-07-05
4
Active Exploitation4
2026-07-06
14
Active Exploitation11Patch3
2026-07-07
6
Active Exploitation5Patch1
2026-07-08
4
Active Exploitation2Disclosure1Patch1
2026-07-09
6
Active Exploitation4Disclosure1Patch1
2026-07-10
1
Disclosure1
2026-07-11
1
Active Exploitation1
2026-07-12
3
Active Exploitation2Patch1
2026-07-13
3
Active Exploitation2Patch1
2026-07-14
3
Active Exploitation3
2026-07-15
6
Active Exploitation6
2026-07-16
2
Active Exploitation1Patch1
2026-07-17
5
Active Exploitation4General1
2026-07-19
2
Active Exploitation1General1
2026-07-20
10
Active Exploitation9Disclosure1
2026-07-21
3
Active Exploitation3
2026-07-22
2
Active Exploitation2
2026-07-23
2
Active Exploitation2
2026-07-27
1
Active Exploitation1
2026-07-29
1
Patch1
2026-07-30
1
Active Exploitation1
2026-08-02
1
Patch1
2026-08-05
1
Active Exploitation1
2026-08-07
1
General1
2026-08-11
5
Active Exploitation5
2026-08-12
9
Active Exploitation6Exploit1Patch1PoC1
2026-08-13
2
Active Exploitation1Patch1
2026-08-14
2
Active Exploitation2
2026-08-17
2
Active Exploitation2
2026-08-23
2
Active Exploitation1Patch1
2026-08-27
1
Disclosure1
2026-08-29
1
Active Exploitation1
2026-08-31
1
Patch1
2026-09-02
1
Patch1
2026-09-03
1
Active Exploitation1
2026-09-12
1
Patch1
>Full discourse20 posts
mRr3b00t@UK_Daniel_Card·
General
CVE-2026-45659 - Edward Snowden's (The SharePoint admin) fave platform has a CVE...
it's in CISA KEV!
https://nvd.nist.gov/vuln/detail/CVE-2026-45659 https://t.co/6Z5w94QTCG
Post summary
The tweet alerts that CVE-2026‑45659 is listed on the CISA KEV and provides NVD links, but offers no technical details, exploit code, or patch information.
⚠️ SharePoint RCE Vulnerability.
Details → https://thehackernews.com/2026/05/microsoft-patches-sharepoint-rce-flaw.html
CVE-2026-45659 allows authenticated attackers with only Site Member permissions to execute code remotely on SharePoint Server.
The CVSS 8.8 flaw affects SharePoint Server 2016, 2019, and Subscription Edition.
Post summary
Microsoft has released a patch for CVE-2026-45659, a remote code execution flaw in SharePoint Server 2016, 2019, and Subscription Edition, rated CVSS 8.8.
🚨Alert🚨 CVE-2026-45659 : A Microsoft SharePoint Server Vulnerability Leading to Remote Code Execution via Deserialization of Untrusted Data.
📊 417.4K+ Services are found on the http://hunter.how yearly.
🔗Hunter
Link:https://hunter.how/list?searchValue=product.name%3D%22SharePoint%20Server%22
HUNTER : http://product.name="SharePoint Server"
📰Refer:https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659
https://thehackernews.com/2026/07/sharepoint-rce-cve-2026-45659-added-to.html
#hunterhow#infosec#infosecurity#OSINT#Vulnerability
Post summary
The post alerts readers to a Microsoft SharePoint Server RCE flaw (CVE‑2026‑45659) and includes a reference to Microsoft's advisory, but no exploit code, active abuse, or patch details are described.
🚨This could be the next big attack even though Microsoft just released an out-of-band patch
CVE-2026-45659: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVSS: 8.8
The vulnerability has been fixed in:
▪️SharePoint Server Subscription Edition, build number 16.0.19725.20280
▪️SharePoint Server 2019, build number 16.0.10417.20128
▪️SharePoint Enterprise Server 2016, build number 16.0.5552.1002.
Post summary
The tweet announces that Microsoft has released an out-of-band patch for CVE-2026-45659, a deserialization flaw in SharePoint that allows code execution over the network, and provides patch details alongside the vulnerability description.
Microsoft has patched a high-severity remote code execution vulnerability in #SharePoint Server.
The issue (CVE-2026-45659, CVSS 8.8) lets an authenticated attacker with basic Site Member permissions run code remotely through deserialization of untrusted data.
No extra privileges are needed.
Post summary
Microsoft patched a high‑severity RCE flaw in SharePoint Server that allowed authenticated Site Member users to execute code via deserialization, requiring no extra privileges.
オンプレでSharePoint Serverを動かしている情シスのみんな、今夜は残業だ。認証済みの一般ユーザ、しかもSite Member権限で管理者級のコードを走らせられる穴が空いた。攻撃者にとってこれほど嬉しい話はない。
・SharePoint Server CVE-2026-45659、CVSS 8.8の認証済み逆シリアライズRCE
Site Member権限なんてどこの部署にも転がっている。みんなの環境で「全員に配った権限」は本当に安全か?退職者アカウントは止まっているか?ログを3回読み返せ、答えはそこにある。
Post summary
Internal staff are alerted that SharePoint Server is vulnerable to an authenticated reverse serialization RCE (CVE-2026-45659, CVSS 8.8), and are urged to review permissions and logs.
⚠️ CISA added CVE-2026-45659 to KEV following active exploitation.
The SharePoint Server RCE was patched in May 2026.
Microsoft says an authenticated Site Member can execute code remotely — no admin rights required.
FCEB agencies have until July 4 to patch.
Details: https://thehackernews.com/2026/07/sharepoint-rce-cve-2026-45659-added-to.html
Post summary
CISA has classified CVE-2026-45659 as a KEV because of active exploitation, Microsoft released a patch in May 2026, and federal agencies are urged to remediate by July 4.
SharePoint Is on Fire Again: What CISA's CVE-2026-45659 Warning Means, and How to Hunt It
https://www.threathunter.ai/blog/sharepoint-cve-2026-45659-cisa-kev-detection-pack/
Post summary
The blog warns of ongoing, real‑world exploitation of SharePoint CVE‑2026‑45659, offering technical insights and hunting guidance while lacking concrete PoC or patch details.
🛡️ We added Microsoft SharePoint Server deserialization of untrusted data vulnerability CVE-2026-45659 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity#InfoSec https://t.co/mfEzA2Kp8m
Post summary
CISA has identified CVE‑2026‑45659, a SharePoint Server deserialization flaw, as a known exploited vulnerability and urges organizations to apply mitigations.
Daniel's Daily Threat Intel & CVE Briefing (from claude)
Tue 15 Jul 2026
Top of the stack: Microsoft's July Patch Tuesday (14 Jul) is the day's priority — a record ~570 Microsoft CVEs with two actively-exploited zero-days, both privilege-escalation bugs in identity infrastructure (AD FS and SharePoint). Patch those two first. In parallel, CISA added a decades-old Cisco IOS CSRF flaw (CVE-2008-4128) to KEV on 13 Jul after confirmed exploitation — audit legacy IOS management planes. Three items are flagged actively-exploited today.
1. CISA KEV / Actively Exploited (lead)
CVE-2008-4128 — Cisco IOS CSRF → arbitrary command execution. Added to KEV 13 Jul 2026; confirmed in-the-wild exploitation of an 18-year-old flaw in the IOS web management interface. So what: internet-exposed or poorly-segmented IOS device web UIs are being abused for command execution — disable the HTTP(S) server or lock it behind ACLs. (SecurityAffairs, SC Media)
CVE-2026-56155 — Microsoft AD FS EoP (CVSS 7.8), actively exploited. Local privilege escalation via insufficient access-control granularity in AD FS (see MS section). (ZDI)
CVE-2026-56164 — Microsoft SharePoint EoP (CVSS 5.3), actively exploited. Missing authentication for a critical function, network-reachable, no user interaction. (BleepingComputer)
Same-week KEV wave (7–10 Jul), all exploited — worth confirming remediation if in scope: Adobe ColdFusion path traversal → RCE (CVE-2026-48282); Langflow auth-bypass/IDOR (CVE-2026-55255) — noted as the first AI-agent platform added to KEV; and Joomla-ecosystem file-upload/access-control bugs (JoomShaper SP Page Builder CVE-2026-48908, Joomlack CVE-2026-56290, Balbooa CVE-2026-56291, iCagenda CVE-2026-48939). (The Hacker News, SecurityWeek)
2. Edge / Network Gear
Quiet in the strict 24–48h window aside from the Cisco IOS KEV item above (CVE-2008-4128) — treat that as the actionable edge item today. No newly-corroborated critical Fortinet/Palo Alto/Citrix/Ivanti/SonicWall advisories published in the last day; the recent SecurityWeek Fortinet/Ivanti critical set (FortiSandbox CVE-2026-25089 CVSS 9.8, Ivanti Sentry CVE-2026-10520 CVSS 10.0) dates to mid-June and should already be in your patch cycle.
3. Microsoft / Windows / Active Directory
Patch Tuesday, 14 Jul 2026 — largest on record. ~570 Microsoft-issued CVEs (≈621 counting all republished/third-party CVEs addressed); 59–63 rated Critical, ~48 of them RCE. (Tenable, ZDI)
CVE-2026-56155 — AD FS EoP (7.8), exploited. Local EoP; high value in federated-identity environments. Patch AD FS servers first.
CVE-2026-56164 — SharePoint EoP (5.3), exploited. Unauthenticated, network-based privilege escalation via missing auth — SharePoint remains under sustained attack (distinct from the CVE-2026-45659 RCE added to KEV on 1 Jul). Patch on-prem SharePoint immediately.
CVE-2026-50661 — BitLocker security-feature bypass, publicly disclosed (not yet exploited). Requires physical access to reach encrypted data — relevant to lost/stolen-device and evil-maid threat models.
So what: two of the three zero-days are identity/domain-compromise primitives — sequence AD FS and SharePoint ahead of the broader 570-CVE backlog.
4. Web / Cloud / DevOps
Adobe ColdFusion CVE-2026-48282 (path traversal → RCE) and Langflow CVE-2026-55255 (auth-bypass IDOR — authenticated users can execute other users' flows) are both actively exploited and in KEV as of this week. If you run ColdFusion or Langflow (LLM/agent app builder), patch now. (http://Threat-Modeling.com)
Adobe's July batch also included a ColdFusion CVSS 9.9 issue (not yet exploited) — standard-priority patch. (ZDI)
No fresh corroborated Kubernetes/critical supply-chain 0-day in the 24h window; ongoing npm/PyPI credential-stealer campaigns continue as background noise.
Watch / developing
Langflow's KEV entry signals attackers are now hunting AI-agent/LLM orchestration platforms as an access vector — inventory any internet-exposed Langflow/agent tooling. Also watch the sheer triage load from the 570-CVE Patch Tuesday: with 48 critical RCEs, expect rapid PoC development over the coming days beyond the three flagged zero-days.
Sign-off: 3 items flagged as actively exploited today (CVE-2026-56155, CVE-2026-56164, CVE-2008-4128), with a cluster of 4–6 additional exploited KEV entries from earlier this week still worth confirming as patched.
Sources:
CISA — CVE-2008-4128 Cisco IOS added to KEV (SecurityAffairs)
ZDI — July 2026 Security Update Review
BleepingComputer — July 2026 Patch Tuesday, 3 zero-days
Tenable — July 2026 Patch Tuesday analysis
The Hacker News — Adobe/Joomla/Langflow KEV additions
SecurityWeek — CISA urges patching ColdFusion, Langflow, Joomla
http://Threat-Modeling.com — CVE-2026-55255 Langflow IDOR
SC Media — CISA adds Cisco IOS flaw to KEV
Post summary
The briefing emphasizes that multiple high‑impact CVEs—particularly Microsoft AD FS and SharePoint privilege‑escalation flaws, and an old Cisco IOS CSRF vulnerability—are actively exploited in the wild, and urges urgent patching.
The text references a Tenable blog about SharePoint CVEs but contains no specific indicators of PoC, exploits, or defenses, suggesting a general mention of the vulnerabilities.
ثغرة (RCE) خطيرة في خوادم (SharePoint)🤷🏻♂️
📍رقم الثغرة (CVE-2026-45659)
📍 تقييمها 8.8
الثغرة تسمح للمهاجم بتنفيذ أوامر عن بُعد والسيطرة على السيرفر بسبب خلل في معالجة البيانات (Deserialization). https://t.co/YjVpAPJJ7V
Post summary
The post announces a critical RCE vulnerability (CVE-2026-45659) in SharePoint with a CVSS score of 8.8, describing a deserialization flaw that could allow remote command execution.
⚠️ Microsoft SharePoint – Remote Code Execution (CVE-2026-45659, CVSS 8.8, CISA KEV)
CISA has added CVE-2026-45659 to its KEV catalogue following evidence of active exploitation. The vulnerability is a deserialization of untrusted data flaw in Microsoft SharePoint that allows an authenticated attacker to execute code remotely over the network. According to Microsoft, an attacker needs only Site Member permissions, with no elevated privileges and no user interaction required, and the flaw is remotely exploitable from the internet.
Affected: SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition.
Mitigation: Apply Microsoft's security updates released on May 21, 2026. Federal agencies must remediate by July 4, 2026 per BOD 26-04. Evaluate each server's internet exposure and prioritise patching for publicly reachable instances.
Modat Magnify Query: technology="Microsoft SharePoint"
The platform: https://magnify.modat.io
Reference: https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-rce-flaw-now-actively-exploited/
#Modat#ModatMagnify#CyberSecurity#ThreatIntelligence#InternetIntelligence#vulnerability#CVE202645659#Microsoft#SharePoint#RCE#infosec#KEV
Post summary
CISA reports CVE-2026-45659 is actively exploited against Microsoft SharePoint, enabling authenticated users to run remote code without elevated privileges; Microsoft issued a patch on May 21, 2026, and agencies are urged to remediate urgently.
The post lists several CVEs that are actively exploited in the wild—particularly the SharePoint RCE—with at least ten companies impacted, but provides no evidence of PoC, patches, or false positives.
Vulnerabilidad de Microsoft SharePoint permite ejecución remota de código
Microsoft ha revelado una vulnerabilidad crítica de seguridad en SharePoint Server (identificada como CVE-2026-45659 )
https://blog.elhacker.net/2026/05/vulnerabilidad-de-microsoft-sharepoint.html
Post summary
Microsoft announced a critical security vulnerability (CVE-2026-45659) in SharePoint Server that allows remote code execution.
🚨 CISA confirma explotación activa de RCE en SharePoint Server (CVE-2026-45659). Solo se necesitan permisos básicos de Site Member. Parche desde mayo, pero ya lo están usando en la vida real.
Si tienes SharePoint on-premise: revisa parches YA.
#SharePoint#CISA#CVE#Empresas https://t.co/QdlrnJS8Dw
Post summary
CISA confirms active exploitation of CVE‑2026‑45659 on SharePoint Server, requiring only basic Site Member permissions, with patches available since May. On‑premise SharePoint users are urged to apply updates immediately.
📢 تنبيه أمني عاجل: مايكروسوفت تصدر تصحيحات أمنية لسد ثغرة خطيرة في SharePoint تسمح بتنفيذ تعليمات برمجية عن بُعد (RCE).
الثغرة (CVE-2026-45659) تحمل تصنيف 8.8 وتؤثر على إصدارات متعددة. يُنصح مدراء الأنظمة بتحديث الخوادم فوراً لضمان الحماية. 🛡️💻 https://t.co/zz476glgAX
Post summary
Microsoft has released patches for CVE-2026-45659, a high‑severity RCE in SharePoint, and urges administrators to update their servers immediately.