CISA: Attackers Are Actively Exploiting a Dangerous Flaw in Microsoft SharePoint
A vulnerability in SharePoint, Microsoft's widely used workplace collaboration platform, lets criminals run malicious code on company servers. Patches have been available since late May. Many organisations haven't applied them.

Key points
- CVE-2026-45659, a high-severity flaw in Microsoft SharePoint Server, was added to CISA's Known Exploited Vulnerabilities catalogue on the same Wednesday CISA issued its warning.
- The US Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies three days to patch, under a standing directive called BOD 26-04.
- Microsoft rated the vulnerability 8.8 out of 10 on the CVSS scale, a standard industry scoring system where 10 is the most severe possible.
- SharePoint Server Subscription Edition, SharePoint Server 2019, SharePoint Server 2016 and SharePoint Enterprise Server 2016 are all affected.
- Microsoft released a fix in late May 2026; any organisation that hasn't applied it is exposed right now.
Criminals are actively breaking into corporate SharePoint servers using a flaw Microsoft patched weeks ago. CISA confirmed active exploitation on Wednesday, adding CVE-2026-45659 to its Known Exploited Vulnerabilities catalogue, a public list of security gaps that attackers are demonstrably using in real attacks. We first covered this CVE on 28 May 2026, and our 2 July report noted attribution details were still thin. They remain so.
SharePoint sits at the heart of many corporate networks, handling document sharing and internal collaboration across millions of organisations. That reach is precisely what makes it a target.
How hard is this to exploit?
Not hard at all. An attacker needs only a basic, low-level account on a targeted SharePoint site, the kind any regular employee holds. From there, they can trigger a deserialization of untrusted data flaw, meaning the server is tricked into accepting and running malicious instructions it should have rejected.
Microsoft's own advisory states the attack requires no "significant prior knowledge of the system" and that criminals can achieve "repeatable success" against vulnerable servers. That is not a complex, specialist attack. It is a reliable, repeatable one.
Once triggered, the attacker can run any code they choose: stealing documents, planting malware (malicious software designed to damage or control a system), or using the SharePoint server as a foothold deeper into the network.
CISA has not published details of the specific attacks it observed. No public reports of exploitation existed before the agency's warning.
Microsoft issued a fix through an out-of-band update in late May, meaning the patch arrived outside its usual monthly schedule because the issue demanded immediate action. It covers all four affected versions.
Should you worry?
If your organisation runs any version of SharePoint Server, yes. Ask your IT team whether the May 2026 patch has been applied. Federal agencies must act within three days under CISA's directive. Every other organisation should move with the same urgency. Review which staff accounts hold SharePoint Site Member permissions or above and remove access that isn't genuinely needed: fewer valid accounts means a narrower window for exploitation.
The blunt read on this one: a reliable, low-skill exploit, weeks of patch availability, and confirmed real-world attacks. The gap between "patch released" and "patch applied" is where organisations keep getting hurt.



