Summary

CISA has added a high-severity Microsoft SharePoint Server vulnerability (CVE-2026-45659) to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The deserialization-of-untrusted-data flaw carries a CVSS score of 8.8 and allows authenticated attackers with Site Member permissions to execute arbitrary code over the network.

Microsoft released patches for SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016 back in May 2026, but organizations have been slow to apply them. Under Binding Operational Directive 26-04, Federal Civilian Executive Branch agencies now have until July 4 to remediate — an unusually tight window that underscores the severity of the threat.

CISA is urging all organizations, not just federal agencies, to prioritize patching this vulnerability immediately given evidence of active exploitation campaigns.

Sources

Commentary

SharePoint servers are high-value targets for attackers because they typically sit at the center of an organization’s document management and collaboration infrastructure. Once an attacker gets code execution on a SharePoint box, the lateral movement opportunities are enormous — access to sensitive documents, internal wikis, credentials stored in configuration files, and often direct paths to Active Directory.

The July 4 deadline for federal agencies is telling. CISA rarely gives a three-day patch window unless they’re seeing exploitation at scale. If your organization runs SharePoint on-premises and hasn’t applied the May patches yet, treat this as a hair-on-fire priority.

By Allan