Critical SharePoint RCE Vulnerability Exploited in the Wild

A critical remote code execution (RCE) vulnerability in Microsoft SharePoint, identified as CVE-2026-45659, is currently being actively exploited. This flaw, stemming from the deserialization of untrusted data, affects on-premises versions of SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Microsoft addressed this issue in an out-of-band update released in late May 2026.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-45659 to its Known Exploited Vulnerabilities (KEV) catalog, confirming its active exploitation in the wild. Notably, attackers require only basic SharePoint permissions, such as those of a Site Member, to execute arbitrary code on unpatched servers. This low barrier to exploitation underscores the urgency for organizations to apply the available patches promptly.

In a related development, another SharePoint vulnerability, CVE-2026-58644, has also been exploited shortly after its disclosure. This critical-severity flaw allows remote, authenticated attackers to execute arbitrary code on the server. Microsoft released a patch for CVE-2026-58644 as part of its July 2026 Patch Tuesday updates. Following reports of active exploitation, CISA added this vulnerability to its KEV catalog, urging federal agencies to address it within three days.

Organizations utilizing on-premises SharePoint deployments are strongly advised to:

  • Apply Microsoft’s security updates for CVE-2026-45659 and CVE-2026-58644 without delay.
  • Monitor SharePoint servers for any signs of unauthorized access or unusual activity.
  • Restrict SharePoint server access to trusted users and networks to minimize exposure.

These vulnerabilities highlight the persistent risks associated with deserialization flaws in web applications. The rapid exploitation of these SharePoint vulnerabilities underscores the importance of timely patching and vigilant monitoring. Organizations must prioritize the application of security updates and implement robust access controls to safeguard their systems against such threats.