Patch Now: SharePoint's Deserialization Demon Is Loose

Patch Now: SharePoint's Deserialization Demon Is Loose

Microsoft once rated this bug “exploitation less likely.” The internet, as it so often does, took that as a challenge. CISA has now confirmed real-world attacks are underway, and if you're still running on-prem SharePoint, this is your cue to stop reading and go patch.

The Bug, in Plain English

CVE-2026-45659 is a remote code execution flaw in Microsoft SharePoint Server, rated 8.8 on the CVSS scale, caused by deserialization of untrusted data — a classic “the server trusted something it really shouldn't have” bug. It hits SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Microsoft shipped a fix back in May 2026, but CISA only added it to the Known Exploited Vulnerabilities catalog on July 1 after confirming attackers were actively using it in the wild.

The scary part is the low bar to entry: any authenticated attacker with nothing more than Site Member permissions can trigger remote code execution, no admin rights required. That's a wide-open door for anyone who's phished, guessed, or bought their way into even a low-privilege account.

Déjà Vu for On-Prem SharePoint

This isn't SharePoint's first rodeo. The 2025 "ToolShell" saga saw the group Storm-2603 exploit on-prem SharePoint flaws to deploy Warlock ransomware, and researchers are eyeing this new CVE with the same nervous energy. Federal agencies were ordered to patch by July 4; everyone else should treat that deadline as their own, because ransomware crews don't check org charts before picking targets.

The real lesson here is less about this specific CVE and more about the pattern: Microsoft's own "exploitation less likely" label turned out to be wrong within weeks, which is a good reminder that vendor severity guesses are a starting point for prioritization, not a substitute for patching promptly.

If your SharePoint server hasn't seen a patch since May, today's the day. The attackers already know your Site Members list — do you?

Source: The Hacker News