Particle.news
Download on the App Store

CISA Adds Microsoft SharePoint RCE to Known Exploited List and Orders Rapid Federal Patching

The deserialization flaw allows low‑privilege authenticated users to run code on vulnerable SharePoint servers, raising urgent risk for unpatched systems.

Overview

  • CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog on Wednesday and directed federal civilian agencies to apply Microsoft’s fixes within three days under BOD 26-04.
  • Microsoft released patches for SharePoint Server Subscription Edition, SharePoint Server 2019, SharePoint Server 2016, and SharePoint Enterprise Server 2016 on May 21 and said the CVE was accidentally omitted from its May update notes.
  • The bug is a deserialization-based remote code execution flaw that any authenticated user with a minimum of Site Member permissions can trigger without admin rights.
  • Security monitors report more than 10,000 internet-exposed SharePoint servers, leaving many organizations at elevated risk if they have not installed Microsoft’s May fixes.
  • Microsoft’s investigation of a recent ransomware incident found parallel intrusions and attributed one cluster to Storm-2603, showing how SharePoint exploits can feed broader ransomware campaigns and complicate detection.