CVE -2026-45659 , a serious Remote Code Execution (RCE) vulnerability affecting Microsoft SharePoint Server , has been officially added to the CISA Known Exploited Vulnerabilities (KEV) list , following confirmed evidence of active exploitation. This move by the US cybersecurity agency is a clear warning signal to organizations worldwide: the vulnerability is already being actively exploited by malicious actors and immediate implementation of the patch is imperative.

CVE-2026-45659 has a CVSS score of 8.8 and is considered a high severity vulnerability, resulting from deserialization of untrusted data. Microsoft had released the corresponding security update in May 2026, covering SharePoint Server Subscription Edition, SharePoint Server 2019 and SharePoint Enterprise Server 2016.Despite the timely release of the patch, many systems remained unpatched, allowing attackers to exploit the security gap.
CISA added the vulnerability to the KEV list on July 1, 2026, giving federal agencies (FCEB) until July 4, 2026 to implement fixes.
See also: Hackers target SharePoint servers with Warlock ransomware
CVE-2026-45659: Technical Details of the SharePoint Vulnerability
According to Microsoft, any authenticated user can activate the vulnerability without requiring administrator or other elevated privileges. Specifically, an attacker with minimal Site Member could remotely execute code on the SharePoint Server via a network attack. This makes the vulnerability particularly dangerous, as the "bar" of entry for the attacker is extremely low.
The vulnerability exploits SharePoint Server 's deserialization mechanism , in which the application processes data from an external source without verifying its integrity. This allows an attacker to inject malicious objects that are automatically executed by the server, bypassing standard security checks. Deserialization vulnerabilities are considered particularly dangerous by security researchers, as they allow arbitrary code execution with minimal user interaction. A similar attack pattern was observed in the Microsoft Exchange vulnerability CVE - 2023-29357 , which led to widespread data breaches.
SharePoint is a central component of corporate IT infrastructure for hundreds of thousands of organizations worldwide, making the impact of the vulnerability extremely large.
It is worth noting that Microsoft had initially marked the vulnerability as “Exploitation Less Likely,” suggesting that its active exploitation came as a surprise. It is currently unknown which malicious actors are behind the attacks, nor what their ultimate goals are. However, the history of similar SharePoint vulnerabilities suggests that groups ransomware are the most likely perpetrators.

Storm-2603: Ransomware via SharePoint
As part of the broader SharePoint threat , Microsoft recently disclosed a particularly complex ransomware case discovered during a routine investigation. Two unrelated attackers were operating simultaneously on the same network, using various techniques to establish persistent access and complicate response efforts. The first group is reported to be Storm-2603 , which is known for deploying the Warlock ransomware by exploiting known vulnerabilities in on-premises SharePoint servers. The initial access appears to have been attempted through the critical vulnerability CVE-2025-11371 (CVSS: 9.1 ), which affects Gladinet Triofox .
See also: CISA: New Zimbra and SharePoint vulnerabilities in the KEV Catalog
Once it gained initial access, Storm-2603 deployed tools such as Velociraptor to disguise malicious actions as legitimate administrative activities. It also created multiple remote access channels via Cloudflare tunneling , Zoho Assist , and SSH connections , configured through Visual Studio Code . The attack escalated by creating new local and domain administrator accounts, and a vulnerable driver ( NSecKrnl.sys ) was used to circumvent endpoint security solutions.
At the same time, traces of a second, unrelated threat actor were discovered that used DLL side-loading and custom backdoors, making attribution even more difficult.
" What may appear to be a single incident ransomware can quickly escalate into something much more complex — spanning multiple organizations, combining tactics, and even involving multiple threat actors operating in parallel ," the Microsoft Incident Response team said .

How to Protect Yourself from CVE-2026-45659
Organizations using Microsoft SharePoint Server should take immediate steps to protect themselves from CVE-2026-45659 and related vulnerabilities. The first and most critical step is to apply the security update that Microsoft released in May 2026 for all versions of SharePoint Server . In addition, it is recommended to implement network segmentation to restrict access to SharePoint servers from the Internet, use firewalls , and limit exposure to only trusted internal networks . Disabling unnecessary deserialization-based features can also significantly reduce the attack surface
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Microsoft: Over 1,300 SharePoint servers vulnerable to spoofing attacks
At the same time, security teams should develop monitoring tools to detect suspicious activity, such as unauthorized code execution or unusual deserialization attempts. Validating and sanitizing all incoming data to SharePoint is also a key defense practice. According to The Hacker News, the vulnerability affects hundreds of thousands of systems worldwide, with a potential economic impact of millions of dollars in ransomware, data recovery costs, and downtime. Any organization that uses SharePoint for document management, collaboration, or intranet services is at risk if the server is not updated.
