logo

High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659)

ID: 17d0eb4b-ae81-55fc-bb87-f51e011546e7

STIX ID: report--17d0eb4b-ae81-55fc-bb87-f51e011546e7

Feed Name: Help Net Security

Threat Score
65/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Zeljka Zorz

...
...

Microsoft has released patches for CVE-2026-45659, a high-severity remote code execution vulnerability in SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. The flaw is due to deserialization of untrusted data and can allow an authenticated attacker to execute code remotely with low attack complexity; Microsoft advises organizations with on-premises SharePoint to apply the provided updates even though no public exploit or PoC has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.