CVE-2026-45659
published 2026-05-22CVE-2026-45659: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
PriorityP186high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-07-04
Exploited in the wild
EPSS
3.22%
86.8th percentile
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < 16.0.5552.1002 | 16.0.5552.1002 |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < 16.0.10417.20128 | 16.0.10417.20128 |
| microsoft | microsoft_sharepoint_server_subscription_edition | >= 16.0.0 < 16.0.19725.20280 | 16.0.19725.20280 |
| microsoft | sharepoint_server | < 16.0.19725.20280 | 16.0.19725.20280 |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2026-45659 is exploitable by any authenticated attacker with a minimum of Site Member permissions (PR:L); monitor for unexpected deserialization activity or remote code execution originating from low-privileged SharePoint accounts ↗
- →Post-exploitation activity following CVE-2026-45659 exploitation includes theft of IIS machine keys and deserialization techniques for persistence and malware deployment; hunt for IIS machine key access and anomalous deserialization events on SharePoint servers ↗
- →Internet-facing on-premises SharePoint Server instances (Subscription Edition, 2019, 2016) are the primary attack surface; prioritize monitoring and patching of externally reachable SharePoint deployments ↗
- ·CVE-2026-45659 does not require administrator or elevated privileges to exploit — standard Site Member permissions are sufficient; access-control-based mitigations alone are insufficient ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
cvelistv5v3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w3mh-jmwv-56f3: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network
ghsa_unreviewed·2026-05-26
CVE-2026-45659 [HIGH] CWE-502 GHSA-w3mh-jmwv-56f3: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
VulDB
Microsoft SharePoint Enterprise Server deserialization
vuldb·2026-05-23
CVE-2026-45659 [CRITICAL] Microsoft SharePoint Enterprise Server deserialization
A vulnerability marked as critical has been reported in Microsoft SharePoint Enterprise Server. Affected by this vulnerability is an unknown functionality. This manipulation causes deserialization.
The identification of this vulnerability is CVE-2026-45659. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
CVEList
Microsoft SharePoint Remote Code Execution Vulnerability
cvelistv5·2026-05-22·CVSS 8.8
CVE-2026-45659 [HIGH] CWE-502 Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
VulnCheck
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
vulncheck·2026·CVSS 8.8
CVE-2026-45659 [HIGH] CWE-502 Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
Affected: Microsoft SharePoint
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Exploitation References: htt
CISA
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
cisa·2026-07-01·CVSS 8.8
CVE-2026-45659 [HIGH] CWE-502 Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Vulnerability: Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Affected: Microsoft SharePoint Server
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Notes:
No detection rules found.
No public exploits indexed.
Tenable
Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness
blogs_tenable·2026-07-21
CVE-2026-63030 Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness
## Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness
Attackers have shifted from hiding from AI tools to running inside them. By poisoning the config files that govern AI coding assistants, a new worm class achieves silent persistence, evades AI-based scanners, and spreads across an organization's repositories through developers' own tools.
## Key takeaways
AI coding assistant configuration files, such as settings.json hooks, .cursorrules Cursor MDC rules, and similar harness files, are now explicit targets in supply-chain attacks, not collateral damage.
These files simultaneously sit at the intersection of three trust relationships: The developer trusts them as config, the integrated development environment (IDE) executes them automatic
Hackernews
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
blogs_hackernews·2026-07-21·CVSS 9.8
CVE-2026-50522 [CRITICAL] Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr .
The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network. Microsoft credited DEVCORE researcher "splitline" with discovering and reporting the flaw.
"In a network-based attack, an attacker authenticated as at least a Site Owner, could w
Tenable
Oracle July 2026 Critical Patch Update Addresses 1235 CVEs
blogs_tenable·2026-07-21
CVE-2026-63030 Oracle July 2026 Critical Patch Update Addresses 1235 CVEs
## Oracle July 2026 Critical Patch Update Addresses 1235 CVEs
Oracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates.
## Key Takeaways
The third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release.
261 issues (18% of all patches) were assigned a critical severity rating
Oracle E-Business Suite received the highest number of patches at 410, accounting for 28.3% of all patches
## Background
On July 21, Oracle released its Critical Patch Update (CPU) for July 2026 , the third quarterly update of the year. This CPU contains fixes for 1235 unique CVEs in 1449 security updates across 32 Oracle product families. Out of the 1449 security updates published this q
Tenable
wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
blogs_tenable·2026-07-20·CVSS 5.9
CVE-2026-63030 [MEDIUM] wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
## wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public proof-of-concept exploits are circulating.
## Key takeaways:
Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve pre-authentication remote code execution against WordPress 6.9.x and 7.0.x installations.
Multiple security firms have confirmed in-the-wild exploitation, with public proof-of-concept exploits appearing w
Hackernews
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
blogs_hackernews·2026-07-17·CVSS 6.5
CVE-2026-58644 [MEDIUM] CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities ( KEV ) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026.
The vulnerability in question is CVE-2026-58644 (CVSS score: 9.8), a critical deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute arbitrary code.
"In a network-based attack, an attacker authenticated as at least a Sit
Tenable
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
blogs_tenable·2026-07-16·CVSS 6.5
CVE-2026-32201 [MEDIUM] CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
## CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments.
## Key Takeaways
CISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware for persistence.
Two additional SharePoint Server vulnerabilities disclosed on July 14, 2026, CVE-2026-55040 and CVE-2026-58644, were not yet
Tenable
The best defenders build AI agents together: Join Tenable for Swarm at Black Hat ’26
blogs_tenable·2026-07-16
CVE-2026-32201 The best defenders build AI agents together: Join Tenable for Swarm at Black Hat ’26
## The best defenders build AI agents together: Join Tenable for Swarm at Black Hat ’26
Agentic AI use is exploding, yet most security teams are building agents in isolation. Tenable is hosting Swarm, a build event at Black Hat 2026, for security practitioners to create and collaborate on agentic, open-source tooling to drive collective defense and stop adversaries together.
## Key takeaways
According to Gartner®, by 2028, an average global Fortune 500 enterprise will have more than 150,000 AI agents in use, up from less than 15 in 2025, generating significant agent sprawl, IT complexity, and management challenges. 1
Security practitioners are building their own agentic, open-source tooling to cut out hours of manual phishing email triage, accelerate threat hunts, and uplevel junior ta
Hackernews
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
blogs_hackernews·2026-07-15
CVE-2026-56164 Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse ) has released a new proof-of-concept (PoC) exploit called LegacyHive.
It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. The Windows User Profile Service, also referred to as ProfSvc, is a core system component that manages user accounts and environments.
"The PoC requires another standard user credential and a third username (which can be an administrator account)," Chaotic Eclipse said . "If the PoC is successful, it will e
Hackernews
SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
blogs_hackernews·2026-07-02·CVSS 8.8
CVE-2026-45659 [HIGH] SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerability, tracked as CVE-2026-45659 (CVSS score: 8.8), is a case of remote code execution arising from the deserialization of untrusted data. The issue was addressed by Microsoft in May 2026 for SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016.
Microsoft not
Hackernews
⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More
blogs_hackernews·2026-06-01·CVSS 7.8
CVE-2026-0257 [HIGH] ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More
Monday hit like a cron job with anger issues.
A busted auth path here, a repo-side faceplant there, some "patched-ish" thing already getting chewed on in the wild, and then the usual bonus round: poisoned dev tools, sketchy forum chatter, phishing kits pretending to be productivity, and AI lowering the bar for people who already thought 'curl | sh' had a personality.
The vibe is simple: old bugs, new wrappers, faster abuse. Patch the obvious crap first. Then read the rest.
## ⚡ Threat of the Week
PAN-OS GlobalProtect Authenticati
Hackernews
Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions
blogs_hackernews·2026-05-26·CVSS 6.5
CVE-2026-45659 [MEDIUM] Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions
Microsoft has rolled out updates to fix a remote code execution vulnerability impacting SharePoint that could be exploited by bad actors in attacks without requiring any specialized conditions to be met.
The vulnerability, tracked as CVE-2026-45659 , carries a CVSS score of 8.8. It has been assigned an important severity.
"Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network," Microsoft said in an advisory released last week.
Microsoft noted that the vulnerability could be tri
2026-05-22
Published
2026-07-01
Added to CISA KEV
Exploited in the wild