Microsoft SharePoint Server Deserialization Remote Code Execution Vulnerability
Severity Level: High
Date: 07/07/2026
Ref: CERT/NCSOC/0244
Components Affected
- Microsoft SharePoint Server 2019 versions earlier than 16.0.10417.20128
- Microsoft SharePoint Enterprise Server 2016 versions earlier than 16.0.5552.1002
- Microsoft SharePoint Server Subscription Edition versions earlier than 16.0.19725.20280
- On-premises Microsoft SharePoint Server deployments running affected x64-based systems
Overview
A high-severity Remote Code Execution (RCE) vulnerability has been identified in Microsoft SharePoint Server. The vulnerability results from insecure deserialization of untrusted data and may allow an authenticated attacker with network access to execute arbitrary code on affected SharePoint servers.
CISA has added CVE-2026-45659 to its Known Exploited Vulnerabilities (KEV) Catalog following evidence of active exploitation. Organizations using affected SharePoint Server versions are strongly advised to apply Microsoft security updates immediately and review exposed SharePoint environments for signs of compromise.
Description
CVE-2026-45659 is classified under CWE-502: Deserialization of Untrusted Data. The vulnerability carries a CVSS v3.1 Base Score of 8.8 (High).
Successful exploitation requires an authenticated low-privileged attacker with network access to the SharePoint server. Because no user interaction is required, exploitation may enable attackers to execute arbitrary code remotely on vulnerable SharePoint systems.
Depending on server configuration and privileges, successful exploitation could allow attackers to execute malicious commands, access sensitive information, modify SharePoint content, deploy additional malware or web shells, and use the compromised server as a pivot point for lateral movement within the internal network.
Impact
- Remote Code Execution
- Unauthorized Code Execution on SharePoint Server
- Sensitive Information Disclosure
- Potential Server Compromise
- Potential Lateral Movement within the Network
- Service Disruption
Solution / Workarounds
Before installation of the software, please visit Microsoft's official security guidance for detailed instructions.
Apply the latest vendor security updates:
- Upgrade Microsoft SharePoint Enterprise Server 2016 to build 16.0.5552.1002 or later.
- Upgrade Microsoft SharePoint Server 2019 to build 16.0.10417.20128 or later.
- Upgrade Microsoft SharePoint Server Subscription Edition to build 16.0.19725.20280 or later.
- Prioritize remediation for internet-facing SharePoint servers.
- Restrict SharePoint administrative access to trusted networks.
- Review SharePoint, IIS, Windows Event, EDR and proxy logs for suspicious activity.
- Review administrative accounts and permissions using the principle of least privilege.
- Verify reliable backups and test restoration procedures.
- If compromise is suspected, isolate affected systems, preserve forensic evidence, rotate credentials, and initiate incident response procedures.
Reference
Disclaimer
The information provided herein is on an "as is" basis, without warranty of any kind.