Microsoft SharePoint Server Deserialization Vulnerability (CVE-2026-45659) - CISA KEV Addition
First seen Jul 4, 2026 · Updated Jul 4, 2026
CISA added CVE-2026-45659, a deserialization of untrusted data vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog due to confirmed active exploitation. Federal civilian agencies are required under BOD 26-04 to remediate this vulnerability on an expedited basis given its potential for full system compromise on publicly exposed assets. All organizations, not just federal agencies, are strongly encouraged to prioritize patching.
Technical Analysis
CVE-2026-45659 is a deserialization of untrusted data vulnerability affecting Microsoft SharePoint Server, which can allow an attacker to craft malicious serialized objects that execute arbitrary code when deserialized by the vulnerable application. This class of vulnerability is a well-established attack vector in enterprise collaboration platforms, often enabling remote code execution (RCE) and full server compromise without authentication in some configurations. Given SharePoint's role as a publicly exposed, internet-facing asset in many organizations, successful exploitation could grant attackers total control of the affected server, enabling lateral movement, data exfiltration, or deployment of secondary payloads. CISA's KEV designation confirms evidence of in-the-wild exploitation, indicating threat actors have operational exploit chains rather than mere proof-of-concept code.
Affected Systems
Microsoft SharePoint Server (on-premises deployments); specific vulnerable versions not detailed in the source alert - organizations should consult Microsoft's official security advisory for CVE-2026-45659 for exact version and patch level applicability.
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) provided in source data; organizations should monitor Microsoft and CISA advisories for updated indicators.
Remediation Steps
- 1
Apply vendor patches immediately
Consult Microsoft's security advisory for CVE-2026-45659 and apply the corresponding SharePoint Server security update without delay.
- 2
Comply with BOD 26-04 requirements
FCEB agencies must remediate this KEV-listed vulnerability within mandated timelines, prioritizing publicly exposed SharePoint assets that could grant total control post-exploitation.
- 3
Check for prior compromise
Per BOD 26-04 guidance, verify whether systems were compromised before the patch was applied by reviewing logs and conducting forensic analysis for signs of exploitation.
- 4
Restrict public exposure
Where feasible, limit direct internet exposure of SharePoint Server instances via network segmentation, VPN access, or web application firewalls until patched.
- 5
Monitor for exploitation indicators
Implement enhanced logging and monitoring on SharePoint servers to detect anomalous deserialization activity, unexpected process spawning, or unauthorized code execution.
- 6
Subscribe to CISA KEV updates
Continuously monitor the CISA KEV Catalog for updates and integrate it into vulnerability management prioritization processes.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.