
Recent SharePoint CVEs (2026) CVE-2026-45659: A high-severity remote code execution flaw affecting on-premises SharePoint Server. It allows authenticated users with basic access to run code, and CISA confirmed active ransomware exploitation. CVE-2026-58644: A critical (CVSS 9.8) remote code execution vulnerability caused by the deserialization of untrusted data, allowing unauthenticated attackers to execute arbitrary code. CVE-2026-55040: A weak authentication/authentication bypass flaw in the JWT token validation pipeline that permits remote unauthenticated attackers to perform operations as a site user or administrator. CVE-2026-50522: A critical 9.8-rated deserialization remote code execution flaw actively targeted by global threat actors to deploy webshells and establish persistence. CVE-2026-56164: A zero-day defect flagged as actively exploited in the wild. CVE-2026-70355: A cross-site scripting vulnerability disclosed in August 2026. #CVE #SharePoint
Post summary
Several SharePoint CVEs are disclosed, many with high CVSS scores and remote code execution weaknesses; key CVEs such as 2026‑45659, 2026‑50522, and 2026‑56164 are confirmed to be actively exploited in the wild.

