Top Advisory

Microsoft SharePoint Server Deserialization Remote Code Execution Vulnerability

Severity Level: High

Date: 07/07/2026

Ref: CERT/NCSOC/0244

Components Affected

Overview

A high-severity Remote Code Execution (RCE) vulnerability has been identified in Microsoft SharePoint Server. The vulnerability results from insecure deserialization of untrusted data and may allow an authenticated attacker with network access to execute arbitrary code on affected SharePoint servers.

CISA has added CVE-2026-45659 to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation. Organizations using affected SharePoint Server versions are strongly advised to apply Microsoft security updates immediately and review exposed SharePoint environments for signs of compromise.

Description

CVE-2026-45659 is classified under CWE-502: Deserialization of Untrusted Data. The vulnerability carries a CVSS v3.1 Base Score of 8.8 (High).

Successful exploitation requires an authenticated low-privileged attacker with network access to the SharePoint server. Because no user interaction is required, exploitation may enable attackers to execute arbitrary code remotely on vulnerable SharePoint systems.

Depending on server configuration and privileges, successful exploitation could allow attackers to execute malicious commands, access sensitive information, modify SharePoint content, deploy additional malware or web shells, and use the compromised server as a pivot point for lateral movement within the internal network.

Impact

Solution / Workarounds

Before installation of the software, please visit Microsoft's official security guidance for detailed instructions.

Apply the latest vendor security updates:

Reference

Disclaimer

The information provided herein is on an "as is" basis, without warranty of any kind.

Footer Advisory