/00 — boot sequence

Hello.

Article

CISA Warns of Active Exploitation: Microsoft SharePoint Server RCE (CVE-2026-45659) Added to KEV Catalog

July 10, 2026•7 min read
security vulnerability sharepoint microsoft cisa cve-2026-45659

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog as of July 1, 2026, confirming active exploitation in the wild. Tracked as CVE-2026-45659 (CVSS 8.8), this remote code execution flaw affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016.

The vulnerability arises from deserialization of untrusted data — a classic but dangerous class of bug that allows an attacker to execute arbitrary code on the target server. Microsoft patched the issue during its May 2026 Patch Tuesday cycle, yet the addition to the KEV catalog signals that threat actors have now weaponized the disclosure.

Vulnerability Details

FieldValue
CVE IDCVE-2026-45659
CVSS Score8.8 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
TypeDeserialization of Untrusted Data → Remote Code Execution
Authentication RequiredYes — Site Member level (not admin)
Attack VectorNetwork-based
Products AffectedSharePoint Server Subscription Edition, SharePoint Server 2019, SharePoint Enterprise Server 2016
Patched InMicrosoft May 2026 Patch Tuesday
CISA KEV AddedJuly 1, 2026
Agency DeadlineJuly 4, 2026

The CVSS vector tells the story: the vulnerability is exploitable over the network (AV:N) with low complexity (AC:L). An authenticated attacker with minimal permissions — just Site Member level (PR:L) — can achieve full compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). No user interaction is required (UI:N), meaning an attacker can chain this with other exploits or automated tooling for broad impact.

Impact Assessment

While Microsoft rated the flaw's exploitation likelihood as "Exploitation Less Likely" in its advisory, the CISA KEV addition contradicts that assessment. The exact exploitation method, attribution, and victimology remain unclear at this time.

What the KEV designation means in practice:

  • Federal Civilian Executive Branch (FCEB) agencies must apply the patch by July 4, 2026, or face regulatory consequences
  • Private sector organizations using SharePoint Server should treat this as an urgent patching priority — the vulnerability is confirmed exploited, and a working exploit exists in the wild
  • All organizations should audit their SharePoint Server deployments for signs of compromise

The vulnerability is especially dangerous in enterprise environments where SharePoint serves as a central document management and collaboration platform. A successful RCE against the SharePoint Server gives attackers access to sensitive documents, credentials, and potentially Active Directory trusts commonly integrated with SharePoint.

Affected Systems

If your organization runs any of these products, you are affected:

  • Microsoft SharePoint Server Subscription Edition — all versions prior to the May 2026 security update
  • Microsoft SharePoint Server 2019 — all versions prior to the May 2026 security update
  • Microsoft SharePoint Enterprise Server 2016 — all versions prior to the May 2026 security update

How to check if you are affected:

  1. Log into your SharePoint Server administration console
  2. Navigate to Settings → About to check the installed version
  3. Compare against the patched version numbers in the Microsoft May 2026 Security Update Guide
  4. Alternatively, check the Windows Update history on the SharePoint server for KB Article IDs from May 2026

Mitigation and Patching

  1. Apply the May 2026 security update immediately. This is the definitive fix for CVE-2026-45659
  2. Verify the patch was applied correctly by checking the SharePoint Server build number against the updated versions listed in the Microsoft Security Response Center advisory
  3. Restrict network access to SharePoint Server where possible — limit exposure to trusted subnets and enforce VPN requirements
  4. Review Site Member permissions — the vulnerability requires only Site Member level, so minimizing the number of members with even this basic access reduces the attack surface
  5. Enable comprehensive logging on SharePoint Servers — monitor for unusual deserialization activity, unexpected process executions, and outbound network connections from the SharePoint Server process

Detection

Organizations should look for these indicators of post-exploitation activity:

  • Velociraptor deployments — the DFIR tool has been used by attackers (including Storm-2603) to blend malicious activity with legitimate administrative behavior
  • Unusual remote access channels — Cloudflare tunnels, Zoho Assist sessions, or SSH connections configured through VS Code originating from the SharePoint Server
  • New administrator accounts — both local and domain-level accounts created outside normal change management
  • Vulnerable driver artifacts — the NSecKrnl.sys driver has been observed used to tamper with endpoint security protections
  • Local File Inclusion probes — requests for files like win.ini and web.config from SharePoint may indicate pre-exploitation reconnaissance

The Storm-2603 Connection

In late June 2026, Microsoft revealed that a routine ransomware investigation uncovered something alarming: two unrelated threat actors operating simultaneously within the same network. One set of attacks was attributed to Storm-2603, a threat actor known for deploying Warlock ransomware — and notably, for exploiting on-premises SharePoint servers since mid-2025.

Microsoft's investigation found that Storm-2603 leveraged known vulnerabilities in SharePoint for initial access, then deployed Velociraptor to masquerade as legitimate administration, established multiple persistence channels, escalated privileges through new accounts, and used a vulnerable kernel driver (NSecKrnl.sys) to disable endpoint security.

"Together, these overlapping activity streams enabled sustained access while masking the full scope of the intrusion," Microsoft's Incident Response team stated. "What may appear to be a single ransomware incident can quickly expand into something more complex — spanning organizations, blending tactics, and even involving multiple threat actors operating in parallel."

While CVE-2026-45659 has not been officially linked to Storm-2603, the actor's established pattern of SharePoint exploitation makes this a plausible vector for their operations.

Frequently Asked Questions

Does this vulnerability require authentication? Yes. An attacker needs valid credentials with at least Site Member permissions (not administrator). However, in enterprise environments with large numbers of SharePoint users, this bar is often low enough for attackers who have already gained a foothold elsewhere.

Can this be exploited remotely? Yes. The attack vector is network-based (AV:N), meaning the attacker does not need physical or local access to the server.

Is there a patch available? Yes. Microsoft released the fix in May 2026. Organizations that have not yet applied this patch are vulnerable.

Does this affect SharePoint Online? The CISA KEV entry specifically references SharePoint Server (on-premises). SharePoint Online customers are not directly affected, though always run updated code.

What is the worst case scenario? An attacker achieving RCE on a SharePoint Server can gain full access to documents, pivot to connected systems, and abuse SharePoint's integration with Active Directory for lateral movement.

How quickly should we patch? Immediately. With CISA confirming active exploitation, any organization running affected versions should treat this as a critical emergency.

Key Takeaways

  • CVE-2026-45659 is a CVSS 8.8 RCE vulnerability in Microsoft SharePoint Server actively exploited in the wild
  • CISA added it to the KEV catalog on July 1, 2026, with a July 4 patching deadline for federal agencies
  • The flaw affects SharePoint Server Subscription Edition, 2019, and 2016 — all on-premises versions
  • An authenticated attacker with Site Member permissions can achieve full server compromise via deserialization of untrusted data
  • The Storm-2603 ransomware group has a proven track record of SharePoint exploitation, making this vulnerability a likely vector for future attacks
  • Beyond patching, organizations should audit for signs of compromise and restrict unnecessary network exposure

Conclusion

The CISA KEV addition of CVE-2026-45659 transforms what could have been a routine Patch Tuesday announcement into an urgent operational priority. For security teams, this is a reminder that on-premises collaboration infrastructure remains a high-value target — and that patch fatigue is not an excuse when active exploitation is confirmed.

SharePoint Server administrators should act now: apply the May 2026 update, audit for indicators of compromise, and review their network exposure controls. In the age of overlapping intrusions and AI-accelerated exploit development, the window between patch availability and weaponization is shrinking fast.


Sources: CISA KEV Catalog | The Hacker News | Microsoft Security Blog | NVD

Automated Transmission

This entry was synthesized and populated dynamically using native API integrations.

Resources & Links