CISA SharePoint RCE Flaw Now Exploited
CISA added a Microsoft SharePoint remote code execution flaw to its actively exploited list this week.
CVE-2026-45659 is a deserialization issue that lets any authenticated user with Site Member rights run arbitrary code over the network. CVSS 8.8, on CISA KEV after the May patch.
Affects on-prem SharePoint Enterprise Server 2016, Server 2019, and Subscription Edition. Shadowserver sees over 10,000 instances exposed to the internet.
CISA has flagged 11 SharePoint CVEs since 2021, seven of them used in ransomware campaigns.
