Skip to main content
CloudKey

Zero-day

Patch Now: SharePoint Server Is Exploited, Federal Deadline July 4

CVE-2026-45659 is an actively exploited deserialization flaw in Microsoft SharePoint Server. CISA added it to KEV on July 1 with a federal deadline of July 4, 2026.

CloudKey rapid-response alert: a fractured glowing padlock over a dark network mesh, marking an actively exploited vulnerability

If you run on-premises Microsoft SharePoint Server and have not yet applied the May 2026 patches, authenticated attackers are already exploiting CVE-2026-45659 to execute arbitrary code on your server. CISA added this flaw to its Known Exploited Vulnerabilities catalog on July 1, 2026, with a federal remediation deadline of July 4.

Am I affected?

CVE-2026-45659 affects the following on-premises SharePoint Server releases, per the Microsoft MSRC advisory and NVD:

  • Microsoft SharePoint Enterprise Server 2016: all builds before 16.0.5552.1002
  • Microsoft SharePoint Server 2019: all builds before 16.0.10417.20128
  • Microsoft SharePoint Server Subscription Edition: all builds before 16.0.19725.20280

SharePoint Online (Microsoft 365 cloud) is not affected. Only on-premises deployments are at risk.

Exploitation requires the attacker to hold a minimum of Site Member permissions on the target server. Organizations with broad internal user access to SharePoint, or whose accounts have been compromised, face the greatest exposure.

What to do now

Apply the patches from the May 2026 Patch Tuesday release immediately:

  • SharePoint Enterprise Server 2016: install KB5002868, which brings the build to 16.0.5552.1002 or later.
  • SharePoint Server 2019: install KB5002870, which brings the build to 16.0.10417.20128 or later.
  • SharePoint Server Subscription Edition: install KB5002863, which brings the build to 16.0.19725.20280 or later.

Updates are available through Windows Update, the Microsoft Update Catalog, and the Microsoft Download Center.

If you cannot patch immediately: Microsoft has not published a supported workaround that fully mitigates this flaw without the patch. As a temporary measure, restrict Site Member-level access to the smallest set of accounts needed for operations. This narrows the attacker pool but does not eliminate the vulnerability.

Federal agencies face a BOD 26-04 deadline of July 4, 2026. That is three days from today. For all other organizations running on-premises SharePoint, treating that window as an internal target is appropriate given confirmed active exploitation.

How it is being exploited

CVE-2026-45659 is a CWE-502 (Deserialization of Untrusted Data) vulnerability with a CVSS 3.1 base score of 8.8 (HIGH), vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, published by NVD on May 22, 2026. An authenticated attacker with Site Member-level access sends a crafted network request that triggers unsafe deserialization in SharePoint Server, resulting in remote code execution on the underlying host. The attack is network-based, requires no user interaction, and carries low attack complexity, meaning repeatable success against unpatched instances is realistic.

CISA’s addition to the KEV catalog on July 1, 2026 reflects confirmed in-the-wild exploitation. EPSS rates this flaw at 2.78 percent (84.6th percentile) as of July 1, 2026. No ransomware campaign use has been confirmed at this writing. For the latest indicators and technical detail, work from the Microsoft advisory and the CISA KEV entry directly.

How VulnMonitor helps

On-premises SharePoint deployments do not always surface in external perimeter scans, particularly when running behind internal load balancers or in segregated network segments. VulnMonitor matches CISA KEV additions against your live asset inventory: if you are running an unpatched SharePoint Enterprise Server 2016, Server 2019, or Subscription Edition instance, this CVE ranks to the top of your remediation queue within minutes of the KEV addition. It does not prevent the exploit, so the patch above is still the action that closes the risk. Knowing exactly which assets are in scope is the first step toward closing it.

Updates

  • 2026-07-01 Initial post. CVE-2026-45659 added to CISA KEV on July 1, 2026. Federal deadline July 4, 2026. No ransomware campaign use confirmed at this writing.

Sources

Security research team

CloudKey Security Research

The CloudKey research team tracks emerging CVEs, exploit chains and active campaigns. Findings feed the platform and the customer advisories that follow.

Weekly brief

The 5-minute patch-priority brief

700+ CVEs drop every week. We send you the few that matter: what is exploited, what to patch first, what to skip.

No data resale. One-click unsubscribe, link in every email. Privacy.