[KEV] CVE-2026-45659 -- CVSS 0.0 Vulnerability Briefing
[KEV] CVE-2026-45659 | CVSS 0.0 (Low) | Exploit: Operational
What Is It
CVE-2026-45659 is a deserialization of untrusted data vulnerability in Microsoft SharePoint Server that allows an authenticated attacker to execute arbitrary code remotely over a network.
Technical Detail
The flaw resides in SharePoint Server's handling of serialized data, where attacker-controlled input is deserialized without adequate validation, enabling remote code execution (RCE). An authorized attacker can trigger the vulnerability by sending a crafted serialized payload over the network to a vulnerable SharePoint instance. Successful exploitation results in code execution in the context of the SharePoint application, which could allow an attacker to compromise the server, access sensitive data, or pivot further into the environment.
Exploitation Status
CISA has confirmed active exploitation in the wild, adding this vulnerability to the Known Exploited Vulnerabilities catalog on July 1, 2026. The exploit maturity is rated Operational, meaning a functional exploit capable of reliable, real-world use exists and is being actively leveraged against targets. This is not limited to proof-of-concept demonstrations.
Who Is Targeting This
No confirmed, ATTAX-verified threat actor attribution is available at this time. Reported attribution indicates no public attribution has been established, with medium confidence. No specific threat group, nation-state origin, or motivation has been publicly linked to observed exploitation activity as of July 5, 2026.
What To Do
Organizations running Microsoft SharePoint Server should treat this as a high-priority patch given CISA's KEV listing and confirmed active exploitation. Per CISA's binding operational directive, federal agencies are required to apply vendor-supplied patches or implement mitigations by the deadline associated with the July 1, 2026 KEV entry. All organizations, regardless of sector, should apply Microsoft's patch for this vulnerability immediately. Until patching is complete, consider restricting network access to SharePoint Server instances, enforcing strict authentication controls, and monitoring SharePoint application logs for anomalous deserialization activity or unexpected process execution originating from SharePoint worker processes. Verify that SharePoint is not directly exposed to the internet unless operationally necessary.