highZero-Day

Microsoft SharePoint Server Deserialization Vulnerability (CVE-2026-45659) - CISA KEV Addition

First seen Jul 4, 2026 · Updated Jul 4, 2026

CISAKEVSharePointdeserializationactive-exploitationBOD-26-04federal-agencies

CISA added CVE-2026-45659, a deserialization of untrusted data vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog due to confirmed active exploitation. Federal civilian agencies are required under BOD 26-04 to remediate this vulnerability on an expedited basis given its potential for full system compromise on publicly exposed assets. All organizations, not just federal agencies, are strongly encouraged to prioritize patching.

Technical Analysis

CVE-2026-45659 is a deserialization of untrusted data vulnerability affecting Microsoft SharePoint Server, which can allow an attacker to craft malicious serialized objects that execute arbitrary code when deserialized by the vulnerable application. This class of vulnerability is a well-established attack vector in enterprise collaboration platforms, often enabling remote code execution (RCE) and full server compromise without authentication in some configurations. Given SharePoint's role as a publicly exposed, internet-facing asset in many organizations, successful exploitation could grant attackers total control of the affected server, enabling lateral movement, data exfiltration, or deployment of secondary payloads. CISA's KEV designation confirms evidence of in-the-wild exploitation, indicating threat actors have operational exploit chains rather than mere proof-of-concept code.

Affected Systems

Microsoft SharePoint Server (on-premises deployments); specific vulnerable versions not detailed in the source alert - organizations should consult Microsoft's official security advisory for CVE-2026-45659 for exact version and patch level applicability.

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) provided in source data; organizations should monitor Microsoft and CISA advisories for updated indicators.

Remediation Steps

  1. 1

    Apply vendor patches immediately

    Consult Microsoft's security advisory for CVE-2026-45659 and apply the corresponding SharePoint Server security update without delay.

  2. 2

    Comply with BOD 26-04 requirements

    FCEB agencies must remediate this KEV-listed vulnerability within mandated timelines, prioritizing publicly exposed SharePoint assets that could grant total control post-exploitation.

  3. 3

    Check for prior compromise

    Per BOD 26-04 guidance, verify whether systems were compromised before the patch was applied by reviewing logs and conducting forensic analysis for signs of exploitation.

  4. 4

    Restrict public exposure

    Where feasible, limit direct internet exposure of SharePoint Server instances via network segmentation, VPN access, or web application firewalls until patched.

  5. 5

    Monitor for exploitation indicators

    Implement enhanced logging and monitoring on SharePoint servers to detect anomalous deserialization activity, unexpected process spawning, or unauthorized code execution.

  6. 6

    Subscribe to CISA KEV updates

    Continuously monitor the CISA KEV Catalog for updates and integrate it into vulnerability management prioritization processes.

CVE / Advisory IDs

CVE-2026-45659

Industries Most Exposed

governmentfederal-agenciestechnologyall-sectors-using-sharepoint

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.