logo

Actively Exploited SharePoint Vulnerability Added to CISA KEV Catalog

ID: cdf3fd22-5fab-5948-b2de-f1eb9892bed6

STIX ID: report--cdf3fd22-5fab-5948-b2de-f1eb9892bed6

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-07-02

Date Updated: 2026-08-06

Author: Do Son

...
...

**CVE-2026-45659 — Microsoft SharePoint RCE (CVSS 8.8):** A remotely exploitable unsafe-deserialization vulnerability in on-premises SharePoint (affecting 2016/2019/Subscription Edition) is being actively exploited in the wild; CISA added it to the KEV catalog and federal agencies were required to patch. Microsoft released fixes (16.0.5552.1002, 16.0.10417.20128, 16.0.19725.20280) and administrators are advised to apply updates immediately, restrict access, audit Site Member permissions, and monitor worker processes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.