← Back to Feed
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
CVE-2026-45659
July 31, 2026 · CISA · Severity: CRITICAL
Microsoft SharePoint Server: Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
Vendor: Microsoft
Product: SharePoint Server
CISA Date Added: 2026-07-01
CVE: CVE-2026-45659
This vulnerability is actively exploited in the wild according to CISA Known Exploited Vulnerabilities catalog.
Key Takeaways
- CVE-2026-45659 is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog.
- The vulnerability involves privilege escalation or authentication bypass, granting unauthorized access to sensitive functions.
- CISA BOD 26-04 requires remediation within the specified due date — apply vendor mitigations promptly.
- Microsoft SharePoint Server: Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.