CISA adds SharePoint vulnerability to its exploited-flaws catalogue

On 1 July CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalogue. NVD describes the flaw as deserialisation of untrusted data in Microsoft Office SharePoint, allowing authorised code execution. Inclusion in KEV means the vulnerability has been observed under exploitation, not merely judged exploitable in theory.

What this means for your organisation

It is the on-premises SharePoint Server installations that need reviewing. SharePoint is usually where the documents with real commercial value live, and a server that is both Internet-facing and behind on patching is a short path to data theft. Organisations running a mix of cloud and on-premises tend to underestimate how many older SharePoint instances are still quietly running.

Berigo recommends

  • Confirm the patch status of every on-premises SharePoint Server instance, including those missing from the service catalogue.
  • Remove direct Internet exposure where access can go through VPN or a controlled publishing solution.
  • Review which identities and service accounts hold rights in SharePoint, and tighten the broadest ones.
  • Use the KEV catalogue as a standing input to vulnerability management, with a shorter deadline for anything listed there.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch