CiberLATAMbywhalemate

CISA Adds Exploited SharePoint Flaw to KEV

CISA added CVE-2026-45659, a Microsoft SharePoint flaw, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. Federal

Whalemate Labs · AI-assisted researchPublished:2 min read

CISA added CVE-2026-45659, a Microsoft SharePoint vulnerability, to its Known Exploited Vulnerabilities catalog on July 1, 2026, after confirming active exploitation. The move triggers a remediation deadline of July 4, 2026 for U.S. federal agencies under Binding Operational Directive 26-04, leaving a three-day window to apply patches and mitigations.

CISA added CVE-2026-45659, a Microsoft SharePoint vulnerability, to its Known Exploited Vulnerabilities catalog on July 1, 2026, after confirming active exploitation. At the same time, the agency set a July 4, 2026 remediation deadline for U.S. federal agencies under Binding Operational Directive 26-04, leaving just three days to deploy patches and mitigations.

What is known about the flaw

NVD describes CVE-2026-45659 as a CWE-502 weakness tied to deserialization of untrusted data in Microsoft Office SharePoint. The affected scope extends across the full SharePoint Server on-premises line, including Subscription Edition, 2019, 2016, and Enterprise 2016.

Available technical analysis indicates that exploitation does not require privileged credentials. According to Threat-Modeling.com, an attacker only needs a standard Site Member or contributor role, with no administrative access required. That broadens the attack surface in collaborative environments with many internal and external users.

Microsoft’s response and defensive measures

CISA’s publication once again highlighted the gap between Microsoft’s initial assessment and the researchers’ reading of the issue. Microsoft still rates the flaw as "Exploitation Less Likely," while CISA added it to KEV after confirming real-world activity. Threat analysis sites have read that mismatch as a recent case of underestimated risk in enterprise collaboration application flaws.

Microsoft’s technical guidance for CVE-2026-45659 includes, in addition to installing the May 2026 patch, enabling AMSI in full mode, deploying Defender Antivirus or an equivalent solution, rotating SharePoint Server ASP.NET machine keys, restarting IIS, and tightening monitoring with Defender for Endpoint or other EDR tools.

Operational risk in Latin America

Nivel4 warns that Microsoft SharePoint is widely used in public and private organizations across Latin America, making active exploitation of CVE-2026-45659 a significant regional risk. Penligent adds that because SharePoint often serves as a central collaboration and automation platform in large organizations, this kind of RCE can become an initial foothold for pivoting into other internal systems.

The same firm recommends that response efforts go beyond patching. Its measures include explicitly verifying the version of each SharePoint Server instance, reviewing logs for signs of exploitation attempts, auditing accounts with Site Member permissions, removing external or guest users where possible, and enforcing MFA whenever feasible. It also recommends proactively hunting for suspicious execution activity on SharePoint servers.

The urgency was also reflected in the incident response community. In professional forums, CVE-2026-45659 was treated as a high-priority "execution surface," with its CVSS 8.8 score, low-privilege authentication requirement, and confirmed active exploitation reinforcing that view.

Under BOD 26-04, adding this flaw to KEV requires U.S. federal agencies to inventory all on-premises SharePoint servers, verify installation of the May 2026 patch, and report remediation status within a maximum of three days.

Sources

View all