CVE detail
CVE-2026-45659
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 4.6
Why it matters now
Mention timeline
- Total mentions
- 17
- within the 30d window
- Peak daily
- 5
- highest bucket
Evidence
Source links by recency
23 source links · newest first
- Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522Security Affairs
Critical SharePoint RCE vulnerability CVE-2026-50522 is under active exploitation after the release of a PoC exploit code. A critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522 (CVSS score of 9.8), is being actively exploited following the release of a
newssecurityaffairs.comJul 21, 2026, 9:38 PM t’s config is now the payload: How attackers are targeting the… By Tom Abai Cyber Exposure Alerts Jul 20 2026 wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about… By Satnam Narang Cyber Exposure Alerts Jul 16 2026 CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions… By Research Special Operations Exposure
vendorwww.tenable.comJul 21, 2026, 9:07 PMs deployments. Key Takeaways CISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware for persistence. Two additional SharePoint Server vulnerabilities disclosed
vendorwww.tenable.comJul 16, 2026, 4:00 PMand advance new models for human-machine collaboration ... Read more Related articles Cyber Exposure Alerts Jul 16 2026 CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions… By Research Special Operations Cyber Exposure Alerts Jul 15 2026 CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities… By Scott Caveza
vendorwww.tenable.comJul 16, 2026, 1:00 PMfrastructure and a disclosure event. Segmentation stops the first from becoming the second.” CISA’s advisory highlights CVE-2026-332201 , CVE-2026-45659 , and the newly added CVE-2026-56164 , all of which have now been confirmed as exploited in the wild and added to the agency’s Known Exploited Vulnerabilities ( KEV ) catalog. Exploitation tells a diffe
newswww.csoonline.comJul 16, 2026, 12:06 PM- CISA sounds alarm over trio of exploited SharePoint flawsThe Register Security
upported version of SharePoint Server on-prem, with three vulnerabilities of particular interest cited. A spoofing bug, CVE-2026-32201 (6.5), was the first to be mentioned. Microsoft disclosed it in March and CISA confirmed it was being actively exploited in June. Additionally, CISA appears concerned by CVE-2026-45659 (8.8) – a remote code execution (R
newswww.theregister.comJul 15, 2026, 3:21 PM s to help security teams improve cybersecurity maturity... Read more Related articles Cyber Exposure Alerts Jul 16 2026 CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions… By Research Special Operations AI Security Jul 16 2026 The best defenders build AI agents together: Join Tenable for Swarm at Black… By Nick Hayes Cyber Expos
vendorwww.tenable.comJul 15, 2026, 12:45 PMicrosoft shipped patches for a record 622 flaws , including two privilege escalation shortcomings in SharePoint Server (CVE-2026-56164, CVSS score: 5.3) and Active Directory Federation Services (CVE-2026-56155, CVSS score: 7.8) that have been flagged as actively exploited. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added both
newsthehackernews.comJul 15, 2026, 11:07 AM- CISA warns admins to patch actively exploited SharePoint flawsBleepingComputer
hree vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. These security flaws (tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) affect all supported self-hosted SharePoint Server versions, including SharePoint Server Subscription Edition (the latest on-premises version, which uses a "continuous update" model)
newswww.bleepingcomputer.comJul 15, 2026, 9:44 AM patched, including two that have been exploited in the wild. Those two are both elevation of privilege vulnerabilities: CVE-2026-56155, an Active Directory Federation Services (AD FS) flaw that allows attackers with limited access to elevate privileges to administrator, and CVE-2026-56164 , a Microsoft SharePoint Server vulnerability. The third is CVE-
newswww.csoonline.comJul 15, 2026, 1:54 AMUpdate July 16, 2026 : CISA has updated this Alert to reflect the addition of CVE-2026-58644 to its Known Exploited Vulnerabilities (KEV) Catalog on July 16, 2026. CISA is aware of active exploitation of vulnerabilities CVE-2026-32201 , CVE-2026-45659 , CVE-2026-56164 , and CVE-2026-58644 , enabling cyber threa
governmentwww.cisa.govJul 14, 2026, 12:00 PMg NERC-CIP compliance, and implement robust security so... Read more Related articles Cyber Exposure Alerts Jul 16 2026 CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions… By Research Special Operations AI Security Jul 16 2026 The best defenders build AI agents together: Join Tenable for Swarm at Black… By Nick Hayes Cyber Expos
vendorwww.tenable.comJul 7, 2026, 6:30 PM- U.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Microsoft SharePoint Server flaw, tracked as CVE-2026-45659 (CVSS score v3.1 of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. At the end of May, Microsoft released security updates […]
newssecurityaffairs.comJul 2, 2026, 3:56 PM - Microsoft said exploitation was 'less likely' ... but CISA just added SharePoint RCE to KEV listThe Register Security
attackers probably wouldn't rush to exploit a newly-patched SharePoint bug hasn't aged especially well. CISA has added CVE-2026-45659, a remote code execution flaw in on-premises Microsoft SharePoint Server, to its Known Exploited Vulnerabilities (KEV) catalog after confirming that crimes are now actively exploiting it in the wild. The bug stems from
newswww.theregister.comJul 2, 2026, 2:40 PM CISA says threat actors are exploiting a recently patched SharePoint remote code execution vulnerability (CVE-2026-45659).
newswww.securityweek.comJul 2, 2026, 10:30 AMts Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-45659 (CVSS score: 8.8), is a case of remote code execution arising from the deserialization of untrusted data. The issue
newsthehackernews.comJul 2, 2026, 5:46 AMone new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-45659 Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Bindin
governmentwww.cisa.govJul 1, 2026, 12:00 PM- June 2026 Patch Tuesday forecast: Where are the CVEs?Help Net Security
June 2026 Patch Tuesday is now live: Record Microsoft Patch Tuesday, fresh zero-day My forecast from last month was only partly right. After the Anthropic Mythos announcements and the deluge of newly discovered vulnerabilities from vendors like Mozilla, Microsoft’s updates were standard fare, 65 CVEs reported in Windows 11 and 58 in Windows 10. The Microsoft Office releases were a bit higher with 19 CVEs or so reported for the online versions. Apple did indeed … More →
newswww.helpnetsecurity.comJun 5, 2026, 6:36 AM - Week in review: Infostealer dropped via FortiClient EMS flaw, exploited Trend Micro Apex One flawHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Coinflow CISO on crypto payments security under AI pressure Crypto payment firms sit near the top of the target list for advanced persistent threat groups, and the workload on their security leaders keeps growing. Malcolm Portelli, CISO at Coinflow, runs the company’s security program from Malta. Coinflow is headquartered in the United States and operates across multiple jurisdictions. Portelli sat … More →
newswww.helpnetsecurity.comMay 31, 2026, 8:00 AM A critical vulnerability, tracked as CVE-2026-45659, in Microsoft SharePoint can allow attackers to achieve remote code execution with little effort. Microsoft released security updates to patch a high-severity SharePoint vulnerability, tracked as CVE-2026-45659 (CVSS score of 8.8), that could allow remote code execution. The flaw does not require complex conditions for exploitation, making it a […]
newssecurityaffairs.comMay 27, 2026, 7:10 AMInformation published. This CVE was addressed by updates that were released in May 2026, but the CVE was inadvertently omitted from the May 2026 Security Updates. This is an informational change only. Customers who have already installed the May 2026 updates do not need to take any further action.
vendormsrc.microsoft.comMay 26, 2026, 2:00 PMMicrosoft has released patches for a high-severity remote code execution vulnerability (CVE-2026-45659) in SharePoint that may be exploited in low-complexity attacks. It affects the SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. About CVE-2026-45659 CVE-2026-45659 stems from Shareoint deserializing untrusted data, and may be exploited by an authenticated attacker to execute code remotely on a vulnerable SharePoint Server instance – no user interaction required. “The attack complexity is Low (AC:L) because … More →
newswww.helpnetsecurity.comMay 26, 2026, 10:44 AMNo excerpt available.
Mitigationwww.cisa.govMay 22, 2026, 11:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.80 · max 1 stars
- amnsecurity/CVE-2026-45659-SharePoint-RCEMedium confidencegithubRepository topic discovery1 starsDiscovered Jul 16, 2026, 12:51 PM
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-58644CVSS 9.8 · Critical
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- CVE-2026-50522CVSS 9.8 · Critical
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- CVE-2026-48560CVSS 5.4 · Medium
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- CVE-2026-45484CVSS 8.8 · High
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- CVE-2026-40368CVSS 8.0 · High
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-40357CVSS 8.8 · High
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.