logo

AL26-015 - Critical vulnerability impacting Microsoft SharePoint Server – CVE-2026-45659

ID: cb0642d3-6bed-58bb-9a8b-adf26eb5e3b0

STIX ID: report--cb0642d3-6bed-58bb-9a8b-adf26eb5e3b0

Feed Name: Canadian Centre for Cyber Security Alerts and Advisories

Threat Score
85/100

Date Published: 2026-07-02

Date Updated: 2026-07-02

Author: Canadian Centre for Cyber Security

...
...

The Canadian Centre for Cyber Security warns of active exploitation of CVE-2026-45659, a critical deserialization vulnerability (CWE-502) in multiple on-premises Microsoft SharePoint Server versions that can enable remote code execution; it lists affected and fixed versions, notes inclusion in CISA’s Known Exploited Vulnerabilities catalog, emphasizes that SharePoint 2016/2019 reach end-of-life on July 14, 2026, and urges organizations to patch, upgrade to supported versions, and follow hardening/segmentation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.