CISA Warns: Actively Exploited SharePoint RCE Vulnerability
CISA Warns: Actively Exploited SharePoint RCE Vulnerability
Urgent Action Required: Actively Exploited SharePoint VulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026...
Urgent Action Required: Actively Exploited SharePoint Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-45659 to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in the wild. This critical remote code execution (RCE) flaw affects Microsoft SharePoint Server and demands immediate attention from system administrators, hosting companies, and any organisation running SharePoint on-premises.

Understanding the Threat
The vulnerability stems from insecure deserialization of untrusted data, a class of flaw particularly dangerous in corporate environments as it can allow an attacker to execute arbitrary code on the server. While exploitation requires authentication, it does not require elevated privileges – a standard account with minimal permissions, similar to a site member role, is sufficient. The attack complexity is low and no user interaction is needed, making it an attractive target for automated attacks, especially if the SharePoint instance is exposed to the internet.
Microsoft's Response and Documentation Oversight
Microsoft released security updates on 21 May 2026 for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. However, the company acknowledged a documentation error: CVE-2026-45659 was not initially listed in that patch cycle. Environments that have fully applied the May updates should be protected, but administrators must verify the patch level to ensure coverage.
Scope of Exposure
Public telemetry suggests more than 10,000 SharePoint servers are exposed to the internet, although this figure does not indicate how many are patched. The risk is amplified for organisations that have not yet applied the updates, as attackers are actively scanning for vulnerable instances.
Remediation Deadlines and Best Practices
CISA has set a remediation deadline of 4 July 2026 for federal agencies under Binding Operational Directive (BOD) 26-04, a clear signal of operational priority when active exploitation is confirmed. For all organisations, the response should involve three key actions:
- Apply Patches Immediately: Install the May 2026 security updates or later versions on all SharePoint farms. Verify that the patches are correctly deployed, as the documentation oversight may lead to oversight.
- Inventory and Reduce Exposure: Identify all SharePoint instances, assess their internet-facing exposure, and implement network segmentation and access controls. If a server does not need to be publicly accessible, restrict access to trusted networks.
- Monitor and Respond: Review logs and telemetry for signs of compromise. Activate incident response procedures if any suspicious activity is detected. Treat any instance not updated before 21 May 2026 as high-risk and accelerate containment and integrity checks.
No Confirmed Campaigns Yet
As of now, no specific campaigns, threat actors, or indicators of compromise have been publicly disclosed. This makes it even more critical to assume that any unpatched SharePoint server could be at risk and to act swiftly.
Protecting Your Infrastructure
Beyond patching, a robust security posture includes proactive measures such as centralised threat intelligence and automated IP blocking. At ALMC.es, we help businesses in Lleida, Barcelona, Tarragona, and Girona strengthen their server security. Our Abuse Shield service centralises protection across your servers, automatically blocking malicious IPs, managing fail2ban across multiple machines, and sharing a reputation feed among all your systems. This layered approach helps mitigate risks from vulnerabilities like CVE-2026-45659 and reduces the attack surface.
Don't wait for an incident to occur. Review your SharePoint deployment today, apply the necessary patches, and consider enhancing your security infrastructure with proactive threat management. Contact ALMC.es to learn how we can help secure your servers and protect your business data.
Related
- GhostLock CVE-2026-43499: Patch Your Linux Servers Now
- RoguePlanet: Microsoft Patches Defender Zero-Day, Update Now
- NPM Supply Chain Attack: How a Malicious SDK Compromised Crypto Wallets
- Desarrollo web
Put these ideas into practice
Talk to ALMC about a solution for your business. Explore your options or contact our team.
