• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-45659: authenticated remote code execution in Microsoft SharePoint Server

An authenticated user with network access can trigger unsafe deserialization in Microsoft SharePoint Server and execute arbitrary code on affected installations. CVE-2026-45659 affects SharePoint Enterprise Server 2016 versions before 16.0.5552.1002, SharePoint Server 2019 versions before 16.0.10417.20128, and SharePoint Server Subscription Edition versions before 16.0.19725.20280. An attacker needs an account with at least low privileged credentials; no user interaction is required beyond sending crafted data over the network.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
8.8HIGH
EPSS
0.02704
CWE
CWE-502
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent: this issue was added to CISA’s Known Exploited Vulnerabilities catalog with a July 4, 2026 federal remediation deadline, so prioritize patching or mitigations immediately for internet-facing or high-value SharePoint servers.

What is CVE-2026-45659?

An authenticated user with network access can trigger unsafe deserialization in Microsoft SharePoint Server and execute arbitrary code on affected installations. CVE-2026-45659 affects SharePoint Enterprise Server 2016 versions before 16.0.5552.1002, SharePoint Server 2019 versions before 16.0.10417.20128, and SharePoint Server Subscription Edition versions before 16.0.19725.20280. An attacker needs an account with at least low privileged credentials; no user interaction is required beyond sending crafted data over the network. The weakness is classified as CWE-502 (Deserialization of Untrusted Data).

Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft SharePoint Server are affected?

BRANCHAFFECTEDFIXED
Microsoft SharePoint Enterprise Server 2016 16.x16.0.0 – before 16.0.5552.100216.0.5552.1002
Microsoft SharePoint Server 2019 16.x16.0.0 – before 16.0.10417.2012816.0.10417.20128
Microsoft SharePoint Server Subscription Edition 16.x16.0.0 – before 16.0.19725.2028016.0.19725.20280

Is CVE-2026-45659 being exploited?

CISA added CVE-2026-45659 to the Known Exploited Vulnerabilities catalog on 2026-07-01, requiring US federal agencies to remediate by 2026-07-04. Public exploit code is also available.

How to fix CVE-2026-45659

  1. Apply vendor updates to versions 16.0.5552.1002 (Enterprise 2016), 16.0.10417.20128 (Server 2019), or 16.0.19725.20280 (Subscription Edition).
  2. If immediate patching is not possible, restrict network exposure of SharePoint servers and limit access to trusted management networks.
  3. Monitor SharePoint logs and implement detection for anomalous deserialization or unexpected remote code execution attempts.
  4. Follow Microsoft guidance and CISA KEV instructions for additional mitigations and forensics triage.

Frequently asked questions

Is CVE-2026-45659 being actively exploited?

CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog on 2026-07-01 (federal due date 2026-07-04), and public exploit code is available.

Which SharePoint Server versions are affected by CVE-2026-45659?

Affected versions are SharePoint Enterprise Server 2016 before 16.0.5552.1002, SharePoint Server 2019 before 16.0.10417.20128, and SharePoint Server Subscription Edition before 16.0.19725.20280.

Is there a patch for CVE-2026-45659?

Yes. Microsoft published fixes: 16.0.5552.1002 for Enterprise 2016, 16.0.10417.20128 for Server 2019, and 16.0.19725.20280 for Subscription Edition.

Does CVE-2026-45659 require authentication?

Yes. The vulnerability requires an authenticated account with at least low privileges to exploit the deserialization flaw in SharePoint Server.

References