CVE-2026-45659Active Exploitation(microsoft / sharepoint_server)

CRITICALCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 49 mentions and remains active

Immediate actions

  • Patch microsoft sharepoint_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-07-04. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-502

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sharepoint_server

Threat summary

  • Active exploitation appears in 173 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 290 mentions across 54 observed days

What's happening

  • Active exploitation reported across 173 signals
  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 16 signals
  • Patch or workaround mentioned in 178 signals
  • Technical details provided in 224 signals
  • Disclosure: 21 classified signals
  • Peaked 38d ago at 49 mentions (2026-07-02); latest day: 1
  • 290 total mentions across 54 days

Affected systems

Vendors
Products
sharepoint_server

2 versions affected across 1 product

Deep dive

Activity timeline290 mentions / 54d
012253749Mentions · 2026-05-23: 1Mentions · 2026-05-26: 33Mentions · 2026-05-27: 34Mentions · 2026-05-28: 6Mentions · 2026-05-30: 3Mentions · 2026-05-31: 3Mentions · 2026-06-01: 1Mentions · 2026-06-03: 1Mentions · 2026-06-08: 4Mentions · 2026-06-09: 2Mentions · 2026-06-11: 1Mentions · 2026-06-12: 1Mentions · 2026-06-18: 2Mentions · 2026-06-28: 1Mentions · 2026-07-01: 4Mentions · 2026-07-02: 49Mentions · 2026-07-03: 27Mentions · 2026-07-04: 6Mentions · 2026-07-05: 4Mentions · 2026-07-06: 14Mentions · 2026-07-07: 6Mentions · 2026-07-08: 4Mentions · 2026-07-09: 6Mentions · 2026-07-10: 1Mentions · 2026-07-11: 1Mentions · 2026-07-12: 3Mentions · 2026-07-13: 3Mentions · 2026-07-14: 3Mentions · 2026-07-15: 6Mentions · 2026-07-16: 2Mentions · 2026-07-17: 5Mentions · 2026-07-19: 2Mentions · 2026-07-20: 10Mentions · 2026-07-21: 3Mentions · 2026-07-22: 2Mentions · 2026-07-23: 2Mentions · 2026-07-27: 1Mentions · 2026-07-29: 1Mentions · 2026-07-30: 1Mentions · 2026-08-02: 1Mentions · 2026-08-05: 1Mentions · 2026-08-07: 1Mentions · 2026-08-11: 5Mentions · 2026-08-12: 9Mentions · 2026-08-13: 2Mentions · 2026-08-14: 2Mentions · 2026-08-17: 2Mentions · 2026-08-23: 2Mentions · 2026-08-27: 1Mentions · 2026-08-29: 1Mentions · 2026-08-31: 1Mentions · 2026-09-02: 1Mentions · 2026-09-03: 1Mentions · 2026-09-12: 1PoC Mentioned / Linked · 2026-05-27: 1PoC Mentioned / Linked · 2026-07-02: 5PoC Mentioned / Linked · 2026-07-03: 1PoC Mentioned / Linked · 2026-07-04: 1PoC Mentioned / Linked · 2026-07-14: 1PoC Mentioned / Linked · 2026-07-20: 2PoC Mentioned / Linked · 2026-08-12: 2PoC Mentioned / Linked · 2026-08-14: 1PoC Mentioned / Linked · 2026-08-17: 1PoC Mentioned / Linked · 2026-08-29: 1Exploit Tool / Code · 2026-07-02: 2Exploit Tool / Code · 2026-07-03: 1Exploit Tool / Code · 2026-07-20: 1Exploit Tool / Code · 2026-08-12: 1Active Exploitation · 2026-05-26: 2Active Exploitation · 2026-05-27: 2Active Exploitation · 2026-05-28: 1Active Exploitation · 2026-06-09: 1Active Exploitation · 2026-07-01: 3Active Exploitation · 2026-07-02: 47Active Exploitation · 2026-07-03: 23Active Exploitation · 2026-07-04: 5Active Exploitation · 2026-07-05: 4Active Exploitation · 2026-07-06: 11Active Exploitation · 2026-07-07: 5Active Exploitation · 2026-07-08: 2Active Exploitation · 2026-07-09: 4Active Exploitation · 2026-07-11: 1Active Exploitation · 2026-07-12: 2Active Exploitation · 2026-07-13: 2Active Exploitation · 2026-07-14: 3Active Exploitation · 2026-07-15: 6Active Exploitation · 2026-07-16: 2Active Exploitation · 2026-07-17: 4Active Exploitation · 2026-07-19: 1Active Exploitation · 2026-07-20: 9Active Exploitation · 2026-07-21: 3Active Exploitation · 2026-07-22: 2Active Exploitation · 2026-07-23: 2Active Exploitation · 2026-07-27: 1Active Exploitation · 2026-07-29: 1Active Exploitation · 2026-07-30: 1Active Exploitation · 2026-08-05: 1Active Exploitation · 2026-08-11: 5Active Exploitation · 2026-08-12: 9Active Exploitation · 2026-08-13: 1Active Exploitation · 2026-08-14: 2Active Exploitation · 2026-08-17: 2Active Exploitation · 2026-08-23: 1Active Exploitation · 2026-08-29: 1Active Exploitation · 2026-09-03: 1Patch / Workaround · 2026-05-26: 28Patch / Workaround · 2026-05-27: 30Patch / Workaround · 2026-05-28: 4Patch / Workaround · 2026-05-30: 3Patch / Workaround · 2026-05-31: 3Patch / Workaround · 2026-06-01: 1Patch / Workaround · 2026-06-08: 2Patch / Workaround · 2026-06-09: 1Patch / Workaround · 2026-06-11: 1Patch / Workaround · 2026-06-18: 1Patch / Workaround · 2026-06-28: 1Patch / Workaround · 2026-07-01: 2Patch / Workaround · 2026-07-02: 19Patch / Workaround · 2026-07-03: 16Patch / Workaround · 2026-07-04: 3Patch / Workaround · 2026-07-05: 3Patch / Workaround · 2026-07-06: 8Patch / Workaround · 2026-07-07: 6Patch / Workaround · 2026-07-08: 3Patch / Workaround · 2026-07-09: 5Patch / Workaround · 2026-07-11: 1Patch / Workaround · 2026-07-12: 2Patch / Workaround · 2026-07-13: 3Patch / Workaround · 2026-07-14: 2Patch / Workaround · 2026-07-15: 4Patch / Workaround · 2026-07-16: 2Patch / Workaround · 2026-07-19: 1Patch / Workaround · 2026-07-20: 1Patch / Workaround · 2026-07-21: 1Patch / Workaround · 2026-07-29: 1Patch / Workaround · 2026-07-30: 1Patch / Workaround · 2026-08-02: 1Patch / Workaround · 2026-08-11: 2Patch / Workaround · 2026-08-12: 6Patch / Workaround · 2026-08-13: 2Patch / Workaround · 2026-08-14: 1Patch / Workaround · 2026-08-17: 2Patch / Workaround · 2026-08-23: 2Patch / Workaround · 2026-08-29: 1Patch / Workaround · 2026-08-31: 1Patch / Workaround · 2026-09-02: 1Technical Details · 2026-05-23: 1Technical Details · 2026-05-26: 33Technical Details · 2026-05-27: 27Technical Details · 2026-05-28: 5Technical Details · 2026-05-30: 3Technical Details · 2026-05-31: 3Technical Details · 2026-06-03: 1Technical Details · 2026-06-08: 4Technical Details · 2026-06-09: 2Technical Details · 2026-06-12: 1Technical Details · 2026-06-18: 2Technical Details · 2026-06-28: 1Technical Details · 2026-07-01: 4Technical Details · 2026-07-02: 42Technical Details · 2026-07-03: 18Technical Details · 2026-07-04: 6Technical Details · 2026-07-05: 4Technical Details · 2026-07-06: 11Technical Details · 2026-07-07: 6Technical Details · 2026-07-08: 3Technical Details · 2026-07-09: 4Technical Details · 2026-07-11: 1Technical Details · 2026-07-12: 2Technical Details · 2026-07-13: 3Technical Details · 2026-07-14: 3Technical Details · 2026-07-15: 4Technical Details · 2026-07-16: 1Technical Details · 2026-07-17: 2Technical Details · 2026-07-19: 1Technical Details · 2026-07-20: 2Technical Details · 2026-07-21: 2Technical Details · 2026-07-22: 1Technical Details · 2026-07-23: 2Technical Details · 2026-07-30: 1Technical Details · 2026-08-02: 1Technical Details · 2026-08-07: 1Technical Details · 2026-08-11: 3Technical Details · 2026-08-12: 4Technical Details · 2026-08-14: 1Technical Details · 2026-08-17: 1Technical Details · 2026-08-23: 2Technical Details · 2026-08-27: 1Technical Details · 2026-08-31: 1Technical Details · 2026-09-02: 1Technical Details · 2026-09-03: 1Technical Details · 2026-09-12: 105-2305-3106-1107-0207-0707-1207-1707-2308-0508-1408-3109-12
Signal classification8 categories
Active Exploitation
16255.9%
Patch
9332.1%
Disclosure
217.2%
General
93.1%
PoC
20.7%
Discovery
10.3%
Referenced assets166 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-231
Disclosure1
2026-05-2633
Active Exploitation2Disclosure2General1Patch28
2026-05-2734
Active Exploitation1Disclosure4General1Patch27PoC1
2026-05-286
Disclosure1General1Patch4
2026-05-303
Patch3
2026-05-313
Disclosure1Patch2
2026-06-011
Patch1
2026-06-031
Disclosure1
2026-06-084
Disclosure1Discovery1Patch2
2026-06-092
Disclosure1Patch1
2026-06-111
Patch1
2026-06-121
General1
2026-06-182
Disclosure1Patch1
2026-06-281
Patch1
2026-07-014
Active Exploitation3Disclosure1
2026-07-0249
Active Exploitation45Disclosure2General1Patch1
2026-07-0327
Active Exploitation22False Positive1General1Patch3
2026-07-046
Active Exploitation5Patch1
2026-07-054
Active Exploitation4
2026-07-0614
Active Exploitation11Patch3
2026-07-076
Active Exploitation5Patch1
2026-07-084
Active Exploitation2Disclosure1Patch1
2026-07-096
Active Exploitation4Disclosure1Patch1
2026-07-101
Disclosure1
2026-07-111
Active Exploitation1
2026-07-123
Active Exploitation2Patch1
2026-07-133
Active Exploitation2Patch1
2026-07-143
Active Exploitation3
2026-07-156
Active Exploitation6
2026-07-162
Active Exploitation1Patch1
2026-07-175
Active Exploitation4General1
2026-07-192
Active Exploitation1General1
2026-07-2010
Active Exploitation9Disclosure1
2026-07-213
Active Exploitation3
2026-07-222
Active Exploitation2
2026-07-232
Active Exploitation2
2026-07-271
Active Exploitation1
2026-07-291
Patch1
2026-07-301
Active Exploitation1
2026-08-021
Patch1
2026-08-051
Active Exploitation1
2026-08-071
General1
2026-08-115
Active Exploitation5
2026-08-129
Active Exploitation6Exploit1Patch1PoC1
2026-08-132
Active Exploitation1Patch1
2026-08-142
Active Exploitation2
2026-08-172
Active Exploitation2
2026-08-232
Active Exploitation1Patch1
2026-08-271
Disclosure1
2026-08-291
Active Exploitation1
2026-08-311
Patch1
2026-09-021
Patch1
2026-09-031
Active Exploitation1
2026-09-121
Patch1
Full discourse20 posts
  • mRr3b00t@UK_Daniel_Card
    General

    CVE-2026-45659 - Edward Snowden's (The SharePoint admin) fave platform has a CVE... it's in CISA KEV! https://nvd.nist.gov/vuln/detail/CVE-2026-45659 https://t.co/6Z5w94QTCG

    Post summary

    The tweet alerts that CVE-2026‑45659 is listed on the CISA KEV and provides NVD links, but offers no technical details, exploit code, or patch information.

    331022811718.4K
    125.0K followersView on X
  • The Hacker News@TheHackersNews
    Patch

    ⚠️ SharePoint RCE Vulnerability. Details → https://thehackernews.com/2026/05/microsoft-patches-sharepoint-rce-flaw.html CVE-2026-45659 allows authenticated attackers with only Site Member permissions to execute code remotely on SharePoint Server. The CVSS 8.8 flaw affects SharePoint Server 2016, 2019, and Subscription Edition.

    Post summary

    Microsoft has released a patch for CVE-2026-45659, a remote code execution flaw in SharePoint Server 2016, 2019, and Subscription Edition, rated CVSS 8.8.

    25531694920.7K
    1.9M followersView on X
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2026-45659 : A Microsoft SharePoint Server Vulnerability Leading to Remote Code Execution via Deserialization of Untrusted Data. 📊 417.4K+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22SharePoint%20Server%22 HUNTER : http://product.name="SharePoint Server" 📰Refer:https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659 https://thehackernews.com/2026/07/sharepoint-rce-cve-2026-45659-added-to.html #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The post alerts readers to a Microsoft SharePoint Server RCE flaw (CVE‑2026‑45659) and includes a reference to Microsoft's advisory, but no exploit code, active abuse, or patch details are described.

    1250924510.2K
    26.0K followersView on X
  • Dark Web Informer@DarkWebInformer
    Patch

    🚨This could be the next big attack even though Microsoft just released an out-of-band patch CVE-2026-45659: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. CVSS: 8.8 The vulnerability has been fixed in: ▪️SharePoint Server Subscription Edition, build number 16.0.19725.20280 ▪️SharePoint Server 2019, build number 16.0.10417.20128 ▪️SharePoint Enterprise Server 2016, build number 16.0.5552.1002.

    Post summary

    The tweet announces that Microsoft has released an out-of-band patch for CVE-2026-45659, a deserialization flaw in SharePoint that allows code execution over the network, and provides patch details alongside the vulnerability description.

    0195643719.4K
    223.7K followersView on X
  • The Hacker News@TheHackersNews
    Patch

    Microsoft has patched a high-severity remote code execution vulnerability in #SharePoint Server. The issue (CVE-2026-45659, CVSS 8.8) lets an authenticated attacker with basic Site Member permissions run code remotely through deserialization of untrusted data. No extra privileges are needed.

    Post summary

    Microsoft patched a high‑severity RCE flaw in SharePoint Server that allowed authenticated Site Member users to execute code via deserialization, requiring no extra privileges.

    221164910.6K
    1.9M followersView on X
  • ボス@サイバーセキュリティの専門家@boss_sec_labo
    Disclosure

    オンプレでSharePoint Serverを動かしている情シスのみんな、今夜は残業だ。認証済みの一般ユーザ、しかもSite Member権限で管理者級のコードを走らせられる穴が空いた。攻撃者にとってこれほど嬉しい話はない。 ・SharePoint Server CVE-2026-45659、CVSS 8.8の認証済み逆シリアライズRCE Site Member権限なんてどこの部署にも転がっている。みんなの環境で「全員に配った権限」は本当に安全か?退職者アカウントは止まっているか?ログを3回読み返せ、答えはそこにある。

    Post summary

    Internal staff are alerted that SharePoint Server is vulnerable to an authenticated reverse serialization RCE (CVE-2026-45659, CVSS 8.8), and are urged to review permissions and logs.

    011046206.3K
    1.2K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ CISA added CVE-2026-45659 to KEV following active exploitation. The SharePoint Server RCE was patched in May 2026. Microsoft says an authenticated Site Member can execute code remotely — no admin rights required. FCEB agencies have until July 4 to patch. Details: https://thehackernews.com/2026/07/sharepoint-rce-cve-2026-45659-added-to.html

    Post summary

    CISA has classified CVE-2026-45659 as a KEV because of active exploitation, Microsoft released a patch in May 2026, and federal agencies are urged to remediate by July 4.

    212250722.8K
    2.3M followersView on X
  • DirectoryRanger@DirectoryRanger
    Active Exploitation

    SharePoint Is on Fire Again: What CISA's CVE-2026-45659 Warning Means, and How to Hunt It https://www.threathunter.ai/blog/sharepoint-cve-2026-45659-cisa-kev-detection-pack/

    Post summary

    The blog warns of ongoing, real‑world exploitation of SharePoint CVE‑2026‑45659, offering technical insights and hunting guidance while lacking concrete PoC or patch details.

    07138236.2K
    37.1K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Microsoft SharePoint Server deserialization of untrusted data vulnerability CVE-2026-45659 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/mfEzA2Kp8m

    Post summary

    CISA has identified CVE‑2026‑45659, a SharePoint Server deserialization flaw, as a known exploited vulnerability and urges organizations to apply mitigations.

    71613689.6K
    301.9K followersView on X
  • LuemmelSec@theluemmel
    Patch

    Out of band SharePoint RCE patch: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659

    Post summary

    Microsoft has released an out‑of‑band patch for CVE‑2026‑45659, addressing a remote code execution flaw in SharePoint.

    110032238.4K
    8.5K followersView on X
  • mRr3b00t@UK_Daniel_Card
    Active Exploitation

    Daniel's Daily Threat Intel & CVE Briefing (from claude) Tue 15 Jul 2026 Top of the stack: Microsoft's July Patch Tuesday (14 Jul) is the day's priority — a record ~570 Microsoft CVEs with two actively-exploited zero-days, both privilege-escalation bugs in identity infrastructure (AD FS and SharePoint). Patch those two first. In parallel, CISA added a decades-old Cisco IOS CSRF flaw (CVE-2008-4128) to KEV on 13 Jul after confirmed exploitation — audit legacy IOS management planes. Three items are flagged actively-exploited today. 1. CISA KEV / Actively Exploited (lead) CVE-2008-4128 — Cisco IOS CSRF → arbitrary command execution. Added to KEV 13 Jul 2026; confirmed in-the-wild exploitation of an 18-year-old flaw in the IOS web management interface. So what: internet-exposed or poorly-segmented IOS device web UIs are being abused for command execution — disable the HTTP(S) server or lock it behind ACLs. (SecurityAffairs, SC Media) CVE-2026-56155 — Microsoft AD FS EoP (CVSS 7.8), actively exploited. Local privilege escalation via insufficient access-control granularity in AD FS (see MS section). (ZDI) CVE-2026-56164 — Microsoft SharePoint EoP (CVSS 5.3), actively exploited. Missing authentication for a critical function, network-reachable, no user interaction. (BleepingComputer) Same-week KEV wave (7–10 Jul), all exploited — worth confirming remediation if in scope: Adobe ColdFusion path traversal → RCE (CVE-2026-48282); Langflow auth-bypass/IDOR (CVE-2026-55255) — noted as the first AI-agent platform added to KEV; and Joomla-ecosystem file-upload/access-control bugs (JoomShaper SP Page Builder CVE-2026-48908, Joomlack CVE-2026-56290, Balbooa CVE-2026-56291, iCagenda CVE-2026-48939). (The Hacker News, SecurityWeek) 2. Edge / Network Gear Quiet in the strict 24–48h window aside from the Cisco IOS KEV item above (CVE-2008-4128) — treat that as the actionable edge item today. No newly-corroborated critical Fortinet/Palo Alto/Citrix/Ivanti/SonicWall advisories published in the last day; the recent SecurityWeek Fortinet/Ivanti critical set (FortiSandbox CVE-2026-25089 CVSS 9.8, Ivanti Sentry CVE-2026-10520 CVSS 10.0) dates to mid-June and should already be in your patch cycle. 3. Microsoft / Windows / Active Directory Patch Tuesday, 14 Jul 2026 — largest on record. ~570 Microsoft-issued CVEs (≈621 counting all republished/third-party CVEs addressed); 59–63 rated Critical, ~48 of them RCE. (Tenable, ZDI) CVE-2026-56155 — AD FS EoP (7.8), exploited. Local EoP; high value in federated-identity environments. Patch AD FS servers first. CVE-2026-56164 — SharePoint EoP (5.3), exploited. Unauthenticated, network-based privilege escalation via missing auth — SharePoint remains under sustained attack (distinct from the CVE-2026-45659 RCE added to KEV on 1 Jul). Patch on-prem SharePoint immediately. CVE-2026-50661 — BitLocker security-feature bypass, publicly disclosed (not yet exploited). Requires physical access to reach encrypted data — relevant to lost/stolen-device and evil-maid threat models. So what: two of the three zero-days are identity/domain-compromise primitives — sequence AD FS and SharePoint ahead of the broader 570-CVE backlog. 4. Web / Cloud / DevOps Adobe ColdFusion CVE-2026-48282 (path traversal → RCE) and Langflow CVE-2026-55255 (auth-bypass IDOR — authenticated users can execute other users' flows) are both actively exploited and in KEV as of this week. If you run ColdFusion or Langflow (LLM/agent app builder), patch now. (http://Threat-Modeling.com) Adobe's July batch also included a ColdFusion CVSS 9.9 issue (not yet exploited) — standard-priority patch. (ZDI) No fresh corroborated Kubernetes/critical supply-chain 0-day in the 24h window; ongoing npm/PyPI credential-stealer campaigns continue as background noise. Watch / developing Langflow's KEV entry signals attackers are now hunting AI-agent/LLM orchestration platforms as an access vector — inventory any internet-exposed Langflow/agent tooling. Also watch the sheer triage load from the 570-CVE Patch Tuesday: with 48 critical RCEs, expect rapid PoC development over the coming days beyond the three flagged zero-days. Sign-off: 3 items flagged as actively exploited today (CVE-2026-56155, CVE-2026-56164, CVE-2008-4128), with a cluster of 4–6 additional exploited KEV entries from earlier this week still worth confirming as patched. Sources: CISA — CVE-2008-4128 Cisco IOS added to KEV (SecurityAffairs) ZDI — July 2026 Security Update Review BleepingComputer — July 2026 Patch Tuesday, 3 zero-days Tenable — July 2026 Patch Tuesday analysis The Hacker News — Adobe/Joomla/Langflow KEV additions SecurityWeek — CISA urges patching ColdFusion, Langflow, Joomla http://Threat-Modeling.com — CVE-2026-55255 Langflow IDOR SC Media — CISA adds Cisco IOS flaw to KEV

    Post summary

    The briefing emphasizes that multiple high‑impact CVEs—particularly Microsoft AD FS and SharePoint privilege‑escalation flaws, and an old Cisco IOS CSRF vulnerability—are actively exploited in the wild, and urges urgent patching.

    33032123.8K
    125.1K followersView on X
  • Thorsten E.@endi24
    General

    SharePoint CVEs FAQ: CVE-2026-56164, CVE-2026-32201, CVE-2026-45659 | Tenable® https://www.tenable.com/blog/cve-2026-32201-cve-2026-45659-cve-2026-56164-faq-sharepoint-server-exploitation

    Post summary

    The text references a Tenable blog about SharePoint CVEs but contains no specific indicators of PoC, exploits, or defenses, suggesting a general mention of the vulnerabilities.

    05023182.8K
    4.7K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    ثغرة (RCE) خطيرة في خوادم (SharePoint)🤷🏻‍♂️ 📍رقم الثغرة (CVE-2026-45659) 📍 تقييمها 8.8 الثغرة تسمح للمهاجم بتنفيذ أوامر عن بُعد والسيطرة على السيرفر بسبب خلل في معالجة البيانات (Deserialization). https://t.co/YjVpAPJJ7V

    Post summary

    The post announces a critical RCE vulnerability (CVE-2026-45659) in SharePoint with a CVSS score of 8.8, describing a deserialization flaw that could allow remote command execution.

    03128117.9K
    50.0K followersView on X
  • Modat@modat_magnify
    Active Exploitation

    ⚠️ Microsoft SharePoint – Remote Code Execution (CVE-2026-45659, CVSS 8.8, CISA KEV) CISA has added CVE-2026-45659 to its KEV catalogue following evidence of active exploitation. The vulnerability is a deserialization of untrusted data flaw in Microsoft SharePoint that allows an authenticated attacker to execute code remotely over the network. According to Microsoft, an attacker needs only Site Member permissions, with no elevated privileges and no user interaction required, and the flaw is remotely exploitable from the internet. Affected: SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. Mitigation: Apply Microsoft's security updates released on May 21, 2026. Federal agencies must remediate by July 4, 2026 per BOD 26-04. Evaluate each server's internet exposure and prioritise patching for publicly reachable instances. Modat Magnify Query: technology="Microsoft SharePoint" The platform: https://magnify.modat.io Reference: https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-rce-flaw-now-actively-exploited/ #Modat #ModatMagnify #CyberSecurity #ThreatIntelligence #InternetIntelligence #vulnerability #CVE202645659 #Microsoft #SharePoint #RCE #infosec #KEV

    Post summary

    CISA reports CVE-2026-45659 is actively exploited against Microsoft SharePoint, enabling authenticated users to run remote code without elevated privileges; Microsoft issued a patch on May 21, 2026, and agencies are urged to remediate urgently.

    04022132.6K
    1.8K followersView on X
  • ボス@サイバーセキュリティの専門家@boss_sec_labo
    Active Exploitation

    今朝のニュースを読んだ。 SharePointが悪用リストに入り、制御装置に穴が空き、サービス提供者が踏まれて10社超が道連れになった。 「影響なし」と言い切れる根拠があるか? ・SharePoint Server CVE-2026-45659、認証済みRCEをCISAがKEV登録 ・AVTECH DGM3103SCT CVE-2026-56808、OS命令注入でroot権限実行 ・三菱電機CNCシリーズ、細工パケットでDoS状態の脆弱性(JVNVU更新) ・加賀ソルネット「アカデミコナビ」、17万件の学生情報漏洩の可能性 ・メール配信「める配くん」不正アクセス、プリマハムら10社超に波及 ・NISC専門家会議、AI高度化に伴うサイバー脅威対策の強化を議論 サービス提供者が踏まれて利用企業が道連れになる手口は、もう珍しくない。 君の組織は「委託しているサービスのリスク」を把握しているか?

    Post summary

    The post lists several CVEs that are actively exploited in the wild—particularly the SharePoint RCE—with at least ten companies impacted, but provides no evidence of PoC, patches, or false positives.

    0302672.5K
    1.5K followersView on X
  • elhacker.NET@elhackernet
    Disclosure

    Vulnerabilidad de Microsoft SharePoint permite ejecución remota de código Microsoft ha revelado una vulnerabilidad crítica de seguridad en SharePoint Server (identificada como CVE-2026-45659 ) https://blog.elhacker.net/2026/05/vulnerabilidad-de-microsoft-sharepoint.html

    Post summary

    Microsoft announced a critical security vulnerability (CVE-2026-45659) in SharePoint Server that allows remote code execution.

    0702161.9K
    140.9K followersView on X
  • Dark Web Informer@DarkWebInformer
    Active Exploitation

    🚨 CISA has added CVE-2026-45659 to the KEV Catalog https://darkwebinformer.com/cisa-kev-catalog/

    Post summary

    CISA has listed CVE‑2026‑45659 in its KEV catalog, indicating it is a known exploited vulnerability.

    13021512.7K
    233.2K followersView on X
  • Es Geeks@EsGeeks
    Active Exploitation

    🚨 CISA confirma explotación activa de RCE en SharePoint Server (CVE-2026-45659). Solo se necesitan permisos básicos de Site Member. Parche desde mayo, pero ya lo están usando en la vida real. Si tienes SharePoint on-premise: revisa parches YA. #SharePoint #CISA #CVE #Empresas https://t.co/QdlrnJS8Dw

    Post summary

    CISA confirms active exploitation of CVE‑2026‑45659 on SharePoint Server, requiring only basic Site Member permissions, with patches available since May. On‑premise SharePoint users are urged to apply updates immediately.

    1501511.2K
    22.4K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Active Exploitation

    ثغرة SharePoint (CVE-2026-45659) الي تكملنا عنها قبل فتره تمت اضافتها الى CISA KEV معناته الثغرة تستغل على نطاق واسع الان https://t.co/ohawF5BdxM

    Post summary

    The tweet indicates that CVE-2026-45659 has been added to the CISA KEV list and is currently being widely exploited.

    000983.6K
    50.1K followersView on X
  • ثامر الغالي@alghali
    Patch

    📢 تنبيه أمني عاجل: مايكروسوفت تصدر تصحيحات أمنية لسد ثغرة خطيرة في SharePoint تسمح بتنفيذ تعليمات برمجية عن بُعد (RCE). الثغرة (CVE-2026-45659) تحمل تصنيف 8.8 وتؤثر على إصدارات متعددة. يُنصح مدراء الأنظمة بتحديث الخوادم فوراً لضمان الحماية. 🛡️💻 https://t.co/zz476glgAX

    Post summary

    Microsoft has released patches for CVE-2026-45659, a high‑severity RCE in SharePoint, and urges administrators to update their servers immediately.

    0101512.8K
    91.0K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftsharepoint_server---
Appmicrosoftsharepoint_server2016--
Appmicrosoftsharepoint_server2019--

Explore more