Skip to main content
CloudKey

CVE

SharePoint and SimpleHelp: two CVEs now confirmed exploited

Two flaws are now confirmed exploited: a Microsoft SharePoint code-execution bug and a SimpleHelp auth bypass, both on CISA KEV this week. Patch them before your CVSS queue.

CloudKey Confirmed-exploited flaws banner for a weekly CVE digest covering Microsoft SharePoint Server and SimpleHelp, both listed on the CISA KEV catalog

Two vulnerabilities are now confirmed exploited: a code-execution flaw in Microsoft SharePoint Server and an authentication bypass in SimpleHelp. CISA added both to its Known Exploited Vulnerabilities (KEV) catalog this week, SharePoint on July 1 and SimpleHelp on June 29, and that listing is the evidence that moves them to the front of a patch queue regardless of what their severity scores say.

Both are worth a closer look for the same reason: their exploitation is confirmed, yet neither carries the sky-high EPSS number you might expect. That mismatch is the whole case for reading KEV as its own signal.

Three acronyms run through this digest. CVSS scores how damaging a flaw would be if someone exploited it, on a 0 to 10 scale. EPSS estimates the chance it gets exploited in the next 30 days, shown here as a percentage. KEV is CISA’s catalog of flaws with confirmed real-world attacks. Severity and likelihood are not the same thing. The full method is in our CVSS vs EPSS vs KEV breakdown.

What’s now confirmed exploited this week

Two CVEs entered the confirmed-exploited column this week. One hits a widely deployed collaboration platform; the other hits a remote-support tool that, once abused, hands an attacker a foothold across every machine it manages. Neither carries an EPSS score above 4%, which is exactly why exploitation evidence, not the model, decides the order here.

CVE-2026-45659: Microsoft SharePoint Server

CVE-2026-45659 is a deserialization of untrusted data flaw (CWE-502) in Microsoft SharePoint Server. An authenticated attacker can send crafted data that the server deserializes without validating it, then run code over the network. The authentication requirement lowers the raw score, but it does not make the flaw safe: a single stolen or low-privilege account becomes a route to code execution on the server.

CVSS base score: 8.8 (High). EPSS: 3.2% (87th percentile). CISA added it to KEV on July 1, 2026.

On-premises SharePoint sits in the middle of document workflows and identity, so a compromised server is rarely contained to the server. Apply Microsoft’s update for the affected builds, then review authentication logs and account privileges on the same host.

CVE-2026-48558: SimpleHelp

CVE-2026-48558 is an authentication bypass (CWE-347, improper verification of a cryptographic signature) in SimpleHelp’s OIDC login flow. When OIDC authentication is configured, the server accepts identity tokens without checking their signature, so a remote, unauthenticated attacker can forge a token carrying arbitrary identity claims and obtain a fully authenticated technician session. In some configurations this also bypasses multi-factor authentication, and no user interaction is required. NVD lists versions 5.5.15 and earlier, plus 6.0 pre-release builds, as affected.

CVSS base score: 10.0 (Critical). EPSS: 1.2% (63rd percentile). CISA added it to KEV on June 29, 2026. FIRST’s CVSS 4.0 metric rates the same flaw 9.5, also Critical.

Remote-support software is a force multiplier for an attacker: a technician session is standing remote access to every endpoint the platform manages. Treat an internet-exposed, OIDC-configured SimpleHelp instance as a priority patch, not a routine one.

CVE-2026-45659 (SharePoint)CVSS 8.8EPSS 3.2%CVE-2026-48558 (SimpleHelp)CVSS 10.0EPSS 1.2%Red: severity if exploited (CVSS, 0 to 10). Blue: modelled 30-day likelihood (EPSS, percent).

Both flaws are confirmed exploited, yet their EPSS likelihood sits under 4%. EPSS is built from public exploitation signals and lags on freshly abused flaws. KEV is the correction: it records what is happening, not what a model predicts.

Why the EPSS numbers stay low

It is tempting to read a 1.2% or 3.2% EPSS score as “unlikely” and defer the patch. That reading breaks down here. EPSS forecasts exploitation from public signals: exploit code, scanner activity, advisory chatter. When a flaw is freshly weaponized, those signals have not accumulated yet, so the score lags reality by days or weeks. KEV closes that gap by recording confirmed exploitation directly.

The practical rule follows from the timeline. Use EPSS to rank the CVEs that are not yet on KEV. Once a CVE is on KEV, its EPSS number is no longer the deciding factor: the exploitation is already confirmed, and the patch is due.

What to change in your queue this week

Three concrete moves for this week’s queue:

  1. Patch both KEV entries first. Apply Microsoft’s SharePoint update on affected servers, and move SimpleHelp past 5.5.15 (or the fixed release per the vendor’s security update) on any OIDC-configured instance. Sort these ahead of higher-CVSS findings that are not on KEV.
  2. Check exposure before you check severity. An internet-facing SimpleHelp server or an on-prem SharePoint reachable from untrusted networks is a different urgency than the same software behind segmentation. Reachability decides how fast the clock runs.
  3. Tag both CVEs with KEV status in your tracker. If your scanner does not export KEV membership, pull the CISA feed and join on CVE ID, so a low EPSS score never buries a confirmed-exploited flaw.

The lesson repeats every week these digests run: the CVEs that earn the first engineering hour are the ones with exploitation evidence behind them, not the ones with the largest severity number. This week that means SharePoint and SimpleHelp, in that order of footprint, both ahead of whatever CVSS-9 advisory is sitting untouched on KEV’s sidelines.

Sources

Security research team

CloudKey Security Research

The CloudKey research team tracks emerging CVEs, exploit chains and active campaigns. Findings feed the platform and the customer advisories that follow.

Weekly brief

The 5-minute patch-priority brief

700+ CVEs drop every week. We send you the few that matter: what is exploited, what to patch first, what to skip.

No data resale. One-click unsubscribe, link in every email. Privacy.