cbcvebase.
CVE-2026-45659
published 2026-05-22

CVE-2026-45659: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

PriorityP186high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-07-04
Exploited in the wild
EPSS
3.22%
86.8th percentile
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Affected

6 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_sharepoint_enterprise_server_2016>= 16.0.0 < 16.0.5552.100216.0.5552.1002
microsoftmicrosoft_sharepoint_server_2019>= 16.0.0 < 16.0.10417.2012816.0.10417.20128
microsoftmicrosoft_sharepoint_server_subscription_edition>= 16.0.0 < 16.0.19725.2028016.0.19725.20280
microsoftsharepoint_server< 16.0.19725.2028016.0.19725.20280
microsoftsharepoint_server
microsoftsharepoint_server

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2026-45659 is exploitable by any authenticated attacker with a minimum of Site Member permissions (PR:L); monitor for unexpected deserialization activity or remote code execution originating from low-privileged SharePoint accounts
  • Post-exploitation activity following CVE-2026-45659 exploitation includes theft of IIS machine keys and deserialization techniques for persistence and malware deployment; hunt for IIS machine key access and anomalous deserialization events on SharePoint servers
  • Internet-facing on-premises SharePoint Server instances (Subscription Edition, 2019, 2016) are the primary attack surface; prioritize monitoring and patching of externally reachable SharePoint deployments
  • ·CVE-2026-45659 does not require administrator or elevated privileges to exploit — standard Site Member permissions are sufficient; access-control-based mitigations alone are insufficient

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
cvelistv5v3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
vulncheck8.8HIGH
cisa8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.