CISA Flags SharePoint Deserialization Bug CVE-2026-45659 as Actively Exploited
The RCE flaw joins KEV with a three-week federal patch deadline. Attribution details remain thin.

Key points
- CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog on Wednesday, citing active exploitation.
- The SharePoint Server flaw carries a CVSS score of 8.8 and enables remote code execution through deserialization of untrusted data.
- An authenticated attacker with sufficient privileges can exploit the flaw over the network.
- SharePoint Online is not affected by on-prem deserialization paths, though hybrid deployments carry inherited risk.
CISA added a high-severity Microsoft SharePoint Server vulnerability to its Known Exploited Vulnerabilities catalog on Wednesday, citing evidence of in-the-wild abuse.
The bug is tracked as CVE-2026-45659. CVSS score: 8.8. Root cause is deserialization of untrusted data leading to remote code execution. An authenticated attacker with the right privileges can trigger the flaw over the network.
What do we actually know?
Less than most readers will want. CISA's KEV listing confirms exploitation; it doesn't name victims, sectors, or operators. No vendor has publicly tied CVE-2026-45659 to a named intrusion set at the time of writing. Single-source attribution here would be premature, and any early claims should be treated as low confidence until a CTI vendor publishes supporting telemetry.
SharePoint on-prem has drawn state-aligned and financially motivated crews for years. The ToolShell cluster earlier this cycle involved actors overlapping with China-nexus groups, though whether CVE-2026-45659 sits in that same operational orbit isn't yet public. We've tracked this CVE since 28 May 2026, and our 27 June report on active exploitation of a deserialization flaw in PTC Windchill is a useful companion read on how these chains develop once operators gain a foothold.
Should you worry about chaining?
Yes, if you're running SharePoint on-prem and internet-facing. Deserialization flaws in SharePoint chain well historically. Operators have paired them with ViewState abuse alongside web shell staging under _layouts or _vti_bin. Earlier ToolShell activity leaned on stolen MachineKey material to forge __VIEWSTATE payloads and maintain access even after patching. Defenders who patched but didn't rotate keys learned that lesson the hard way.
SharePoint Online isn't affected by on-prem deserialization paths, though tenants federated with compromised on-prem farms inherit risk through hybrid identity.
What should defenders do right now?
Apply the relevant Microsoft security update immediately and verify the build number on every farm node, not just the WFE you happened to RDP into. After patching, rotate SharePoint MachineKeys and restart IIS. Assume prior compromise if the server was internet-facing.
Hunt for anomalous w3wp.exe child processes, unexpected .aspx files under SharePoint layout directories, and outbound connections from SharePoint service accounts to non-Microsoft infrastructure. Constrain SharePoint egress at the network layer. There's rarely a legitimate reason for a content server to initiate arbitrary outbound HTTPS.
Expect a vendor writeup in the coming days. Patch and rotate now; hunt while you wait.



