The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned on Wednesday that attackers have begun exploiting a high-severity Microsoft SharePoint remote code execution vulnerability. Tracked as CVE-2026-45659, this security flaw stems from a deserialization of untrusted data weakness, and it allows attackers with low privileges to execute arbitrary code on unpatched SharePoint servers in low-complexity attacks that don't require user interaction. "Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges. In a network-based attack, an authenticated attacker, who has a minimum of Site Member permissions (PR:L), could execute code remotely on the SharePoint Server," Microsoft explains. "The attack vector is Network (AV:N) because this vulnerability is remotely exploitable and can be exploited from the internet. The attack complexity is Low (AC:L) because an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component." Microsoft released security updates for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition to address this vulnerability on May 21, saying that the CVE had been accidentally omitted from the May 2026 Security Updates. Internet security watchdog group Shadowserver is currently tracking over 10,000 SharePoint servers exposed online. However, there is no ...
CISA: Microsoft SharePoint RCE flaw now actively exploited
BleepingComputer
·Sergiu Gatlan
·Published Jul 2, 2026
·Updated
Affected Software
3 affected components
Microsoft SharePoint Enterprise Server 2016=2016
Microsoft SharePoint Server 2019=2019
Microsoft SharePoint Server Subscription Edition=Subscription Edition
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a high-severity remote code execution vulnerability in Microsoft SharePoint that is being actively exploited.
2
What security implications are discussed in the article?
The article highlights the risk of remote code execution attacks due to the vulnerability in Microsoft SharePoint.
3
What products or software are affected by this vulnerability?
The vulnerability affects Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition.
4
What is the CVE tracking number for the SharePoint vulnerability?
The vulnerability is tracked as CVE-2026-45659.
5
When did CISA publish the warning about the SharePoint vulnerability?
CISA published the warning on July 2, 2026.