CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability
The United States Cybersecurity and Infrastructure Security Agency (CISA) has recently issued a critical alert concerning a high-severity vulnerability within Microsoft SharePoint Server that is actively being exploited in the wild. This flaw, tracked as CVE-2026-45659, is categorized as a deserialization of untrusted data bug. It enables authenticated attackers, even those with only Site Member permissions, to execute arbitrary code on affected SharePoint servers without requiring elevated privileges.
Microsoft had addressed this particular vulnerability with an out-of-band security update released in late May. However, CISA's recent warning highlights that despite the patch being available, malicious actors are now actively leveraging this defect to compromise systems. The ease of exploitation is a significant concern, as Microsoft itself noted that an attacker does not need extensive prior knowledge of the system and can achieve repeatable success with their payload against the vulnerable component.
In response to the active exploitation, CISA has added CVE-2026-45659 to its Known Exploited Vulnerabilities (KEV) catalog. This action mandates that federal agencies apply the necessary patches within a strict three-day timeframe, as per Binding Operational Directive (BOD) 26-04. While CISA has not disclosed specific details about the observed attacks, the inclusion in the KEV catalog underscores the immediate and severe risk this vulnerability poses.
Organizations utilizing Microsoft SharePoint Server, including SharePoint Server Subscription Edition, SharePoint Server 2019, SharePoint Server 2016, and SharePoint Enterprise Server 2016, are strongly advised to apply Microsoft's patches without delay. SharePoint serves as a critical backbone for document sharing, intranet services, and collaboration within many enterprises, making it a frequent target for cyberattacks. Proactive patching is essential to protect against potential data breaches and system compromises.
Read original source