CISA adds Microsoft SharePoint RCE CVE-2026-45659 to KEV amid active exploitation
Source headline: SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
Intelligence Summary
CISA has added a high-severity Microsoft SharePoint Server remote code execution flaw, CVE-2026-45659, to its KEV catalog. The issue involves RCE caused by deserialization of untrusted data. CISA cited evidence indicating the vulnerability is being actively exploited in the wild. With a reported CVSS score of 8.8, the flaw presents a serious risk to exposed SharePoint deployments. Organizations should check whether they are affected and apply the vendor’s recommended fixes or mitigations immediately.
Recommended Action
Check whether your SharePoint Server deployment is affected by CVE-2026-45659 (CVSS 8.8) and apply the vendor fix. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.