SharePoint RCE Flaw (CVE-2026-45659) Added to CISA's Exploited List — What Your Business Needs to Do Now

A remote code execution vulnerability in Microsoft SharePoint Server is being actively exploited in the wild and was just added to CISA's Known Exploited Vulnerabilities catalog. Here is what SMBs running SharePoint need to know.

Volturion Security Team6 min read
vulnerabilityrceweb-securitymicrosoft

If your company runs Microsoft SharePoint Server to manage internal documents, intranet pages, or team collaboration, you need to pay attention to what just happened. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a SharePoint vulnerability, CVE-2026-45659, to its Known Exploited Vulnerabilities (KEV) catalog on July 1, 2026, confirming that attackers are actively using it against real organizations right now. CISA has given federal agencies until July 4 to patch, which tells you exactly how urgent this is treated inside the security community, and it should be treated with the same urgency by any small or medium business running the affected software.

What was discovered

CVE-2026-45659 is a deserialization of untrusted data vulnerability in Microsoft SharePoint Server, tracked under CWE-502. In plain terms, SharePoint takes in data from a network request and converts, or "deserializes," it back into an internal object without properly checking what that data actually contains. If an attacker crafts that data carefully, they can trick SharePoint into executing arbitrary code on the server instead of just processing normal information.

The vulnerability carries a CVSS score of 8.8, which NVD classifies as High severity, sitting just below the Critical band. What makes this flaw dangerous in practice is not the number alone, it is the fact that Microsoft's own advisory and CISA's KEV listing confirm it is being exploited by attackers today, not in a lab, not theoretically, but in live campaigns against real SharePoint deployments. An attacker only needs low-level authenticated access and no user interaction to trigger it, which is a much lower bar than it sounds when you consider how many SharePoint instances have loosely managed internal accounts, shared service credentials, or guest access enabled for contractors and partners.

Which systems are affected

The vulnerability affects on-premises Microsoft SharePoint Server deployments. This is the version of SharePoint that many small and medium businesses run themselves, on their own servers or in their own cloud infrastructure, rather than through Microsoft's fully managed SharePoint Online service. Companies choose this setup for a range of reasons: tighter control over sensitive documents, integration with legacy internal systems, compliance requirements that call for data residency, or simply because they never migrated off an older deployment.

If your business uses SharePoint for HR records, contracts, financial documents, client files, or internal wikis, and that SharePoint instance is self-hosted rather than cloud-managed, you are in the affected population. This also extends to any third-party vendor, IT provider, or agency that manages a SharePoint environment on your behalf. Even a partially patched or delayed-patch environment remains exposed until the fix is fully applied across every server in the farm.

How attackers are exploiting it

Deserialization vulnerabilities like this one follow a fairly consistent attack pattern, and CISA's active exploitation confirmation tells us this one is no exception:

  • Gaining a foothold — The attacker first needs low-privileged authenticated access to the SharePoint environment. This can come from a phished employee credential, a reused password found in a prior breach, an over-permissioned guest account, or a compromised third-party integration.
  • Crafting the malicious payload — Using knowledge of how SharePoint deserializes objects internally, the attacker constructs a specially formatted data object designed to trigger unintended code execution when the server processes it.
  • Delivering the payload — The crafted object is submitted through a SharePoint API endpoint or web request that the attacker's authenticated account has access to reach.
  • Remote code execution — Once SharePoint deserializes the malicious object, the attacker's code runs directly on the server with the permissions of the SharePoint application, effectively handing them a foothold inside your network.
  • Escalation and lateral movement — From that foothold, attackers commonly move to dump credentials stored on the server, access connected file shares and databases, deploy additional malware, or pivot to other systems on the same internal network.

This mirrors exactly the kind of campaign that has hit SharePoint before. Prior SharePoint deserialization and authentication flaws have been used by ransomware affiliates and espionage-focused threat actors alike, because a compromised document management server sits at the center of a company's most sensitive files and often has trusted connections to other internal systems.

What is the real business impact

A compromised SharePoint server is not a minor incident, it is frequently a company-wide one. SharePoint typically sits at the intersection of HR, legal, finance, and operational documentation, meaning a successful attacker can access contracts, employee personal data, financial statements, and strategic plans in a single breach. According to IBM's Cost of a Data Breach Report, the average cost of a data breach in 2025 reached $4.88 million globally, with breaches involving business email or document systems taking noticeably longer to identify and contain than other attack types, which directly increases the total cost.

For a small or medium business, this kind of breach is rarely just a financial line item. Regulatory obligations, client trust, and contractual penalties for exposing partner or customer data can compound quickly. Verizon's Data Breach Investigations Report has repeatedly found that the majority of breaches at smaller organizations trace back to a single exploited vulnerability or stolen credential that went unpatched or unnoticed for weeks or months, exactly the window an unpatched CVE-2026-45659 creates. If your SharePoint environment also connects to email systems, shared drives, or single sign-on, the blast radius of a single compromised server extends far beyond the document library itself.

What you should do right now

  1. Identify every SharePoint Server instance your company runs, including any managed by third-party IT providers or agencies. Do not assume you know the full inventory, shadow deployments spun up years ago for a single project are common.
  2. Apply Microsoft's security update for CVE-2026-45659 immediately on every affected server. Do not wait for a routine patch cycle, this vulnerability is being actively exploited today.
  3. Review authentication controls on your SharePoint environment. Disable unused guest or service accounts, enforce multi-factor authentication for every account with SharePoint access, and remove excess permissions that go beyond what a user's role requires.
  4. Check logs for signs of prior compromise, including unusual authentication activity, unexpected file downloads, or new administrative accounts created without approval. Deserialization exploits can be difficult to spot after the fact, so look specifically around the timeframe this flaw became known.
  5. Restrict internet exposure where possible. If your SharePoint server does not need to be reachable directly from the public internet, put it behind a VPN or internal-only access and reduce the attack surface available to opportunistic scanners.
  6. Confirm the fix took effect across every node in a multi-server SharePoint farm, not just the primary server, since a single unpatched node can undermine the whole remediation effort.

How Volturion helps

Volturion's vulnerability scanning continuously checks your public-facing infrastructure against CVE-specific detection signatures, including flaws like CVE-2026-45659, so you know immediately if an unpatched, vulnerable version of an affected system is exposed rather than discovering it after CISA or a security researcher does. Every finding Volturion surfaces is scored by severity and mapped to its CVE, CWE, and OWASP classification, giving your team a clear, prioritized view of what to fix first instead of a raw list of technical alerts you have to research yourself.

Beyond detection, Volturion's AI-powered remediation engine generates step-by-step guidance tailored to the specific vulnerability found and your environment, so your team can move from "we have a critical flaw" to "here is exactly what to patch and how" without needing an in-house security specialist. If your business does not have a dedicated security team, and most SMBs do not, this is precisely the kind of fast-moving, actively exploited vulnerability that continuous monitoring is designed to catch before attackers find it first.

Security Platform

Is your site protected against these vulnerabilities?

Volturion continuously scans your sites and code, detects vulnerabilities like the ones covered here, and gives you AI-generated remediation steps. No security team needed.