CISA orders federal agencies to patch SharePoint flaw by Saturday as attacks begin
A newly exploited Microsoft SharePoint bug lands in CISA's Known Exploited Vulnerabilities Catalog, triggering a three-day patching clock under Binding Operational Directive 26-04.

Key points
- CISA confirmed on Wednesday that attackers are exploiting CVE-2026-45659, a high-severity flaw in Microsoft SharePoint Server.
- Federal civilian agencies must patch by Saturday under Binding Operational Directive 26-04, issued last month.
- Microsoft released fixes on May 21 for SharePoint Enterprise Server 2016, SharePoint Server 2019 and SharePoint Server Subscription Edition.
- Shadowserver counts more than 10,000 SharePoint servers exposed to the open internet.
- Since 2021, CISA has flagged 11 SharePoint bugs as exploited in the wild, with seven tied to ransomware attacks.
CISA told federal agencies on Wednesday to fix a serious flaw in Microsoft SharePoint within days. Attackers are already using it.
The bug, tracked as CVE-2026-45659, lets an attacker who already holds a basic user account run their own code on the server, effectively taking it over. SharePoint is the software many organisations use to store internal documents and run team websites.
Microsoft's advisory is direct. "Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges," the company writes. The minimum "Site Member" permission is enough. The attack travels over the network, can be launched from the internet, and Microsoft rates its complexity as low, meaning it works reliably without special conditions.
We covered this vulnerability first on 3 July, when patches had been available for weeks and many organisations still hadn't applied them. The window for painless remediation is closing.
What is CISA actually requiring, and by when?
CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities Catalog on Wednesday, giving Federal Civilian Executive Branch agencies until Saturday to patch. That deadline flows from Binding Operational Directive 26-04, a rule issued last month that replaced raw severity scores with a four-factor test: whether the flaw appears in the KEV catalog, whether exploitation can be automated at scale, whether the system faces the internet, and whether a successful attack hands over partial or full control.
All four tests apply here. The directive also says agencies must "follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable." That last clause, pull the plug if you can't patch, is the sharpest enforcement lever CISA holds short of a formal emergency directive.
Federal civilian agencies are bound. Private companies aren't. But CISA's KEV listings are widely treated as a de facto patching standard by insurers and auditors, so the practical reach extends well past the legal one.
How did we get here?
Microsoft released the fix on May 21. The company acknowledged the CVE had been "accidentally omitted" from the May 2026 Security Updates bundle, a bookkeeping slip that likely delayed some patching cycles.
This is the second SharePoint bug this year to reach the KEV catalog. Microsoft patched a separate SharePoint zero-day, a flaw exploited before any fix existed, in its April 2026 Patch Tuesday release, as first reported by BleepingComputer.
Shadowserver, a nonprofit that scans the public internet, is tracking more than 10,000 SharePoint servers reachable online. How many have installed the May update is unknown.
What should organisations do now?
Install the May 21 update. If a SharePoint server faces the internet and can't be patched immediately, take it offline until it can be.
CISA has tagged 11 SharePoint vulnerabilities as actively exploited since 2021, with seven feeding ransomware campaigns, the kind that locks a company's files until it pays. That pattern is the real story here: SharePoint servers sit at the centre of corporate file systems, which makes them valuable targets and means the blast radius of a successful intrusion is rarely small. Treat this as the same category of risk, not a routine update.



