Skip to main content

CVE detail

CVE-2026-45659

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVSS 8.8 · HighBuzz score 79.6KEV listed1 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 79.6

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 4.6
Mention score
30.0
23 evidence mentions in the snapshot
Diversity score
20.0
11 sources across 4 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
4.6
1 repos · best confidence 0.80
Best PoC traction
1
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
17
within the 30d window
Peak daily
5
highest bucket

Evidence

Source links by recency

Newest mentions first
23 source links · newest first
  • Critical SharePoint RCE vulnerability CVE-2026-50522 is under active exploitation after the release of a PoC exploit code. A critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522 (CVSS score of 9.8), is being actively exploited following the release of a

    newssecurityaffairs.comJul 21, 2026, 9:38 PM
  • t’s config is now the payload: How attackers are targeting the… By Tom Abai Cyber Exposure Alerts Jul 20 2026 wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about… By Satnam Narang Cyber Exposure Alerts Jul 16 2026 CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions… By Research Special Operations Exposure

    vendorwww.tenable.comJul 21, 2026, 9:07 PM
  • s deployments. Key Takeaways CISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware for persistence. Two additional SharePoint Server vulnerabilities disclosed

    vendorwww.tenable.comJul 16, 2026, 4:00 PM
  • and advance new models for human-machine collaboration ... Read more Related articles Cyber Exposure Alerts Jul 16 2026 CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions… By Research Special Operations Cyber Exposure Alerts Jul 15 2026 CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities… By Scott Caveza

    vendorwww.tenable.comJul 16, 2026, 1:00 PM
  • frastructure and a disclosure event. Segmentation stops the first from becoming the second.” CISA’s advisory highlights CVE-2026-332201 , CVE-2026-45659 , and the newly added CVE-2026-56164 , all of which have now been confirmed as exploited in the wild and added to the agency’s Known Exploited Vulnerabilities ( KEV ) catalog. Exploitation tells a diffe

    newswww.csoonline.comJul 16, 2026, 12:06 PM
  • CISA sounds alarm over trio of exploited SharePoint flawsThe Register Security

    upported version of SharePoint Server on-prem, with three vulnerabilities of particular interest cited. A spoofing bug, CVE-2026-32201 (6.5), was the first to be mentioned. Microsoft disclosed it in March and CISA confirmed it was being actively exploited in June. Additionally, CISA appears concerned by CVE-2026-45659 (8.8) – a remote code execution (R

    newswww.theregister.comJul 15, 2026, 3:21 PM
  • s to help security teams improve cybersecurity maturity... Read more Related articles Cyber Exposure Alerts Jul 16 2026 CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions… By Research Special Operations AI Security Jul 16 2026 The best defenders build AI agents together: Join Tenable for Swarm at Black… By Nick Hayes Cyber Expos

    vendorwww.tenable.comJul 15, 2026, 12:45 PM
  • icrosoft shipped patches for a record 622 flaws , including two privilege escalation shortcomings in SharePoint Server (CVE-2026-56164, CVSS score: 5.3) and Active Directory Federation Services (CVE-2026-56155, CVSS score: 7.8) that have been flagged as actively exploited. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added both

    newsthehackernews.comJul 15, 2026, 11:07 AM
  • hree vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. These security flaws (tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) affect all supported self-hosted SharePoint Server versions, including SharePoint Server Subscription Edition (the latest on-premises version, which uses a "continuous update" model)

    newswww.bleepingcomputer.comJul 15, 2026, 9:44 AM
  • patched, including two that have been exploited in the wild. Those two are both elevation of privilege vulnerabilities: CVE-2026-56155, an Active Directory Federation Services (AD FS) flaw that allows attackers with limited access to elevate privileges to administrator, and CVE-2026-56164 , a Microsoft SharePoint Server vulnerability. The third is CVE-

    newswww.csoonline.comJul 15, 2026, 1:54 AM
  • Update July 16, 2026 : CISA has updated this Alert to reflect the addition of CVE-2026-58644 to its Known Exploited Vulnerabilities (KEV) Catalog on July 16, 2026. CISA is aware of active exploitation of vulnerabilities CVE-2026-32201 , CVE-2026-45659 , CVE-2026-56164 , and CVE-2026-58644 , enabling cyber threa

    governmentwww.cisa.govJul 14, 2026, 12:00 PM
  • g NERC-CIP compliance, and implement robust security so... Read more Related articles Cyber Exposure Alerts Jul 16 2026 CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions… By Research Special Operations AI Security Jul 16 2026 The best defenders build AI agents together: Join Tenable for Swarm at Black… By Nick Hayes Cyber Expos

    vendorwww.tenable.comJul 7, 2026, 6:30 PM
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Microsoft SharePoint Server flaw, tracked as CVE-2026-45659 (CVSS score v3.1 of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. At the end of May, Microsoft released security updates […]

    newssecurityaffairs.comJul 2, 2026, 3:56 PM
  • attackers probably wouldn't rush to exploit a newly-patched SharePoint bug hasn't aged especially well. CISA has added CVE-2026-45659, a remote code execution flaw in on-premises Microsoft SharePoint Server, to its Known Exploited Vulnerabilities (KEV) catalog after confirming that crimes are now actively exploiting it in the wild. The bug stems from

    newswww.theregister.comJul 2, 2026, 2:40 PM
  • CISA says threat actors are exploiting a recently patched SharePoint remote code execution vulnerability (CVE-2026-45659).

    newswww.securityweek.comJul 2, 2026, 10:30 AM
  • ts Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-45659 (CVSS score: 8.8), is a case of remote code execution arising from the deserialization of untrusted data. The issue

    newsthehackernews.comJul 2, 2026, 5:46 AM
  • one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-45659 Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Bindin

    governmentwww.cisa.govJul 1, 2026, 12:00 PM
  • June 2026 Patch Tuesday is now live: Record Microsoft Patch Tuesday, fresh zero-day My forecast from last month was only partly right. After the Anthropic Mythos announcements and the deluge of newly discovered vulnerabilities from vendors like Mozilla, Microsoft’s updates were standard fare, 65 CVEs reported in Windows 11 and 58 in Windows 10. The Microsoft Office releases were a bit higher with 19 CVEs or so reported for the online versions. Apple did indeed … More →

    newswww.helpnetsecurity.comJun 5, 2026, 6:36 AM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Coinflow CISO on crypto payments security under AI pressure Crypto payment firms sit near the top of the target list for advanced persistent threat groups, and the workload on their security leaders keeps growing. Malcolm Portelli, CISO at Coinflow, runs the company’s security program from Malta. Coinflow is headquartered in the United States and operates across multiple jurisdictions. Portelli sat … More →

    newswww.helpnetsecurity.comMay 31, 2026, 8:00 AM
  • A critical vulnerability, tracked as CVE-2026-45659, in Microsoft SharePoint can allow attackers to achieve remote code execution with little effort. Microsoft released security updates to patch a high-severity SharePoint vulnerability, tracked as CVE-2026-45659 (CVSS score of 8.8), that could allow remote code execution. The flaw does not require complex conditions for exploitation, making it a […]

    newssecurityaffairs.comMay 27, 2026, 7:10 AM
  • Information published. This CVE was addressed by updates that were released in May 2026, but the CVE was inadvertently omitted from the May 2026 Security Updates. This is an informational change only. Customers who have already installed the May 2026 updates do not need to take any further action.

    vendormsrc.microsoft.comMay 26, 2026, 2:00 PM
  • Microsoft has released patches for a high-severity remote code execution vulnerability (CVE-2026-45659) in SharePoint that may be exploited in low-complexity attacks. It affects the SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. About CVE-2026-45659 CVE-2026-45659 stems from Shareoint deserializing untrusted data, and may be exploited by an authenticated attacker to execute code remotely on a vulnerable SharePoint Server instance – no user interaction required. “The attack complexity is Low (AC:L) because … More →

    newswww.helpnetsecurity.comMay 26, 2026, 10:44 AM
  • No excerpt available.

    Mitigationwww.cisa.govMay 22, 2026, 11:16 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

1 repository references · best confidence 0.80 · max 1 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence