AI Stories on SHORT INFO are generated & curated with AI
unverified 02 Jul, 19:09

CISA flags actively exploited Microsoft SharePoint RCE CVE-2026-45659

US federal agencies have until July 4 to patch a Microsoft SharePoint $MSFT flaw CISA says is under active attack. CVE-2026-45659 (CVSS 8.8) lets any authenticated user with basic Site Member rights run code on-prem. Attacker and method are still unknown, so unpatched servers car

Every organization still running Microsoft $MSFT SharePoint on its own servers has a hard deadline this week. CISA has added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog, confirming the remote code execution flaw is already being used in real attacks. The bug carries a CVSS score of 8.8 and stems from the way SharePoint deserializes untrusted data. What makes it dangerous is the low bar for abuse: an attacker only needs authenticated access with basic Site Member permissions, not administrator rights, to run code on the server. Microsoft shipped patches back in May for SharePoint Server Subscription Edition, Server 2019 and Enterprise Server 2016, so a fix exists, but unpatched systems remain exposed. US federal civilian agencies have been ordered to remediate by July 4. For now, neither the identity of the attackers nor the exact exploitation method has been made public, which means defenders are working without a clear picture of who is targeting them. On-premises SharePoint remains a recurring entry point for intruders, and the short remediation window signals how seriously the agency is treating this one. Patching immediately and reviewing server access logs is the practical response.

#cyber
Published on
BlueskyFacebookThreadsX