CISA Flags Actively Exploited SharePoint RCE CVE-2026-45659 — Patch Now

Manish Garg
Manish Garg Associate of (ISC)² · RingSafe
Jul 2, 2026
2 min read

Last updated: July 6, 2026

CISA has added a high-severity Microsoft SharePoint Server flaw to its CISA KEV (KEV) catalog after confirming it is being exploited in the wild. Tracked as CVE-2026-45659 (CVSS 8.8), the bug is a remote code execution vulnerability arising from deserialization of untrusted data — and the bar for abusing it is uncomfortably low.

Why this one is dangerous

Any authenticated attacker can trigger the flaw without admin or elevated privileges. An account with nothing more than Site Member permissions is enough to execute code remotely on the SharePoint server. In practice that means a single phished user, a stale contractor account, or a password-sprayed mailbox with SharePoint access becomes a path to full server compromise. US federal civilian agencies were ordered to patch by 4 July 2026 — a deadline that signals how seriously CISA is treating the active exploitation, as reported by The Hacker News and SecurityWeek.

The India angle

On-premises SharePoint remains deeply embedded in Indian enterprises, PSUs, and the GCC/captive units that run document workflows for global parents. Many of these farms sit one patch cycle (or several) behind. Two things follow:

  • Internal accounts are the attack surface — deprovisioning discipline matters as much as patching. Audit who still holds Site Member access, especially vendors and ex-employees.
  • Exploitation is a CERT-In reportable incident — unauthorised access to a server triggers the 6-hour reporting clock. If you run regulated workloads, wire SharePoint alerts into your integrated breach playbook now, not after.

What security teams should do now

Patch SharePoint Server to the fixed build immediately — this is in the KEV catalog, so treat the deadline as already passed. Where patching lags, restrict SharePoint to VPN-only access, review IIS and ULS logs for deserialization errors and unexpected w3wp.exe child processes, and rotate credentials for any account with recent anomalous SharePoint activity. This flaw pairs badly with the credential-theft campaigns we covered in the June 2026 Patch Tuesday roundup — an attacker who already holds low-value credentials just got a server-takeover primitive.

Worried about your exposure?

Get a free attack-surface review

We check what an attacker would see about your business — leaked credentials, exposed services, dark-web mentions. 30 minutes, no obligation.

Book exposure review Replies in 4 working hrs · India-only · Senior consultants