CVE-2026-45659
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Description as published by the source, in English.
Key facts
- Published
- 2026-05-22
- Last modified
- 2026-07-23
- Assigned by
- secure@microsoft.com
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H- Scored by
- secure@microsoft.com
- Probability of exploitation
-
9.1 %
higher than 95 %
of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15 - Fix available
- Not registered in the sources
Actively exploited
CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-07-01, with a remediation deadline of 2026-07-04 for US federal agencies.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| Microsoft | Sharepoint Server | < 16.0.19725.20280 | Affected |
| Microsoft | Sharepoint Server | 2016 | Affected |
| Microsoft | Sharepoint Server | 2019 | Affected |
Weakness type
-
CWE-502: Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-45659
Related at Berigo
Articles
-
CISA adds SharePoint vulnerability to its exploited-flaws catalogue
Mentions this CVE
2026-07-01
On 1 July CISA added CVE-2026-45659 to the KEV catalogue, a deserialisation flaw in Microsoft Office SharePoint allowing code execution.
-
A fake CAPTCHA gets the user to open a tunnel into the network
Same product
2026-09-01
Microsoft has tracked the TerminalFix campaign, in which compromised websites show a fake Cloudflare CAPTCHA and ask visitors to paste a command into…
-
A Word macro was the way in at defence manufacturers and government bodies
Same product
2026-09-01
Insikt Group has mapped a campaign in which macro-enabled Word documents planted the HOOKEDGE backdoor at defence manufacturers, government bodies an…
-
Attackers are letting npm mirrors host their fake Cloudflare page
Same product
2026-08-27
OX Security has identified 24 malicious npm packages that all carry the same fake Cloudflare page. Installing them does no harm, but mirrors such as …
Does this affect you?
A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.