CVE-2026-45659 · Critical · CISA KEV
Microsoft SharePoint Server Deserialization Vulnerability Exploited In The Wild
Threat Engine Auto-Feed · data current as of 2026-07-01
CVE-2026-45659, a deserialization of untrusted data vulnerability in Microsoft SharePoint Server, allows an authorized attacker to execute code over a network. This vulnerability is listed in CISA KEV, indicating active exploitation. Its EPSS score is in the 85th percentile, suggesting a higher likelihood of future exploitation.
- CVSS:
- EPSS percentile: 0.8461
- Exploitation pressure: 76/100 (Critical)
Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 85th percentile. Threat × Vulnerability from public signals — impact depends on your environment.
Weakness —
Deserialization of untrusted data occurs when an application converts data from an external source back into an object without properly validating its contents. If an attacker can control this external data, they can inject malicious code that the application will then execute when it attempts to deserialize the data.
Who's at risk
Exposure: unknown · Auth: unknown · unknown
Enterprise profiles most at risk
- Organizations heavily reliant on Microsoft SharePoint Server for collaboration and document management
- Financial services organizations (due to assessed targeting by FIN7, LockBit affiliates, APT38)
- Technology sector organizations (due to assessed targeting by APT29, Scattered Spider)
Misconfigurations that escalate it
- Insufficient network segmentation that allows unauthorized access to SharePoint servers
- Overly permissive user accounts or service accounts within the SharePoint environment
- Lack of robust input validation mechanisms for data processed by SharePoint
High-impact scenarios
- Remote Code Execution (RCE) leading to full compromise of the SharePoint server
- Data exfiltration from sensitive documents stored on SharePoint
- Lateral movement within the network from a compromised SharePoint server
- Disruption of critical business operations relying on SharePoint services
Likely adversaries
- FIN7 — Financial services (Assessed)
- LockBit affiliates — Financial services (Assessed)
- APT38 (Lazarus) — Financial services (Assessed)
- APT29 (Cozy Bear) — Technology (Assessed)
- Scattered Spider — Technology (Assessed)
What to do (defensive)
Detect
- Monitor SharePoint server logs for unusual process execution or network connections originating from the server
- Implement network intrusion detection systems (NIDS) to identify anomalous traffic patterns to/from SharePoint servers
- Regularly audit SharePoint user and service account permissions for least privilege adherence
Contain
- Isolate affected SharePoint servers from the broader network if compromise is suspected
- Restrict network access to SharePoint servers to only necessary ports and trusted sources
- Implement multi-factor authentication for all SharePoint administrative interfaces
Patch
- Apply the latest security updates and patches released by Microsoft for SharePoint Server immediately
Frontier verdict — Critical
Critical priority due to active exploitation in the wild (CISA KEV) and high EPSS, enabling authorized attackers to achieve remote code execution on Microsoft SharePoint Server.
For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.