CVE-2026-45659
Actively exploited. CVE-2026-45659 is listed in the CISA Known Exploited Vulnerabilities catalog (added 2026-07-01) — exploitation has been observed in the wild, and US federal agencies are required to remediate it under BOD 22-01. Treat patching as urgent.
Public exploit code is available. Proof-of-concept or working exploit code for CVE-2026-45659 is indexed in GitHub PoC. Expect opportunistic scanning and exploitation attempts — prioritize remediation.
Update July 16, 2026 : CISA has updated this Alert to reflect the addition of CVE-2026-58644 to its Known Exploited Vulnerabilities (KEV) Catalog on July 16, 2026. CISA is aware of active exploitation of vulnerabilities CVE-2026-32201 , CVE-2026-45659 , CVE-2026-56164 , and CVE-2026-58644 , enabling cyber threat actors to gain unauthorized access to on-premises SharePoint Server instances. These vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution (RCE) and post-exploitation activities, such as stealing Internet Information Services (IIS) machine keys and performing deserialization techniques, to gain persistence and deploy malware. Organizations should monitor affected SharePoint Servers closely for any signs of exploitation or unusual activity. Additionally, the following newly disclosed CVE is not yet known to have been exploited, but Microsoft has identified it as posing a potential risk if left unpatched: CVE-2026-55040 CISA urges organizations to detect and remediate a potential compromise by implementing the following recommendations: Apply the latest patches and security updates from Microsoft, verify that installation completes successfully, and shorten patching cycles when possible. Verify that Antimalware Scan Interface (AMSI) integration is enabled for each SharePoint web application. Follow Microsoft’s Configure AMSI integration with SharePoint Server guidance to ensure proper configuration and select the “Full Mode” option for the Request Body Scan Mode, where feasible. When compromise is expected, use the following AMSI and Microsoft Defender Antivirus (MDAV) detections, and implement your organization’s incident response plan for any positive detections: AMSI: Exploit:Script/SuspSignoutReqBody.A – request body scanning; SharePoint Server Subscription only; Microsoft has blocked observed attempts. AMSI: Exploit:Script/ToolPaneAuthBypass.A – req
CSIRTS triage
- What
- Active exploitation of vulnerabilities in SharePoint Server allows unauthorized access and potential remote code execution.
- Who is affected
- Organizations using supported on-premises SharePoint Server versions.
- Urgency
- Remediation is urgent due to active exploitation and the potential for severe impact.
- Action
- Organizations should monitor affected SharePoint Servers and apply patches as they become available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-45659
Get an email if CVE-2026-45659 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Exploitation confirmedAlready exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 95% of all EPSS-scored CVEs.
Exploit availability
Public exploit or proof-of-concept code for CVE-2026-45659 is indexed in these free datasets. Available exploit code raises real-world risk independent of the CVSS score.
- GitHub PoCPublic proof-of-concept repositories on GitHub reference this CVE.look it up ↗
Advisory coverage (6)
- criticalexploited2026-009: Critical Vulnerabilities in Microsoft SharePointcert-eu · 2026-07-23
- unknownexploitedCISA Urges SharePoint Hardening After New Exploitationscisa · 2026-07-14
- criticalexploitedAL26-015 - Critical vulnerability impacting Microsoft SharePoint Server – CVE-2026-45659cccs · 2026-07-02
- high[UPDATE] [high] Microsoft SharePoint Server 2016 and SharePoint Server 2019: Vulnerability allows code executi…cert-bund · 2026-07-02
- highexploitedCISA Adds One Known Exploited Vulnerability to Catalogcisa · 2026-07-01
- criticalexploitedCVE-2026-45659: Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerabilitycisa-kev · 2026-07-01
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-45659)