The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding the active exploitation of a high-severity vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-45659. On July 2, 2026, CISA added this flaw to its Known Exploited Vulnerabilities (KEV) catalog, emphasizing the immediate risk to organizations worldwide.

Understanding the Vulnerability: CVE-2026-45659

CVE-2026-45659 is described as a deserialization of untrusted data bug, affecting multiple versions of Microsoft SharePoint Server. This flaw allows authenticated attackers to execute arbitrary code on vulnerable SharePoint servers. The impact is severe, as successful exploitation could grant attackers full control over the compromised server, leading to data breaches, system disruption, or further network penetration.

Microsoft had previously released an out-of-band security update in late May to address this vulnerability. However, CISA's recent alert confirms that threat actors have been actively exploiting this flaw in the wild, indicating that many organizations have yet to apply the crucial patch. The vulnerability is considered easy to exploit, requiring only a minimum of Site Member permissions, without needing other elevated privileges. This low barrier to entry makes it particularly attractive to attackers.

Affected Versions and Urgency

The vulnerability impacts SharePoint Server Subscription Edition, SharePoint Server 2019, SharePoint Server 2016, and SharePoint Enterprise Server 2016. CISA's directive, mandated by Binding Operational Directive (BOD) 26-04, compels federal civilian executive branch agencies to patch this vulnerability within three days of its addition to the KEV catalog. This strict timeline underscores the severity and the widespread potential for harm if the vulnerability remains unpatched. The inclusion in the KEV catalog means there is definitive evidence of active exploitation, making patching not just a recommendation but a critical security imperative.

Protecting Your Organization

Organizations running affected versions of Microsoft SharePoint Server must prioritize patching immediately. The following steps are crucial for mitigating the risk:

1. Apply Security Updates Immediately: Ensure that all affected Microsoft SharePoint Server instances have the out-of-band security update released in late May for CVE-2026-45659 applied without delay. 2. Verify Patch Installation: After applying the patch, verify its successful installation across all SharePoint environments. 3. Monitor for Suspicious Activity: Implement enhanced monitoring for your SharePoint environments and associated networks to detect any signs of exploitation or unauthorized access. Look for unusual activity, privilege escalation attempts, or unexpected changes to configurations. 4. Review Access Controls: Regularly review and enforce the principle of least privilege for all SharePoint users and administrators. Ensure that only necessary personnel have access to sensitive areas. 5. Conduct Regular Audits: Perform periodic security audits and penetration tests on your SharePoint infrastructure to identify and address potential weaknesses before they can be exploited.

The active exploitation of CVE-2026-45659 serves as a stark reminder of the persistent threats facing enterprise software and the importance of a proactive patching strategy.