Microsoft patches high-severity SharePoint RCE vulnerability CVE-2026-45659
By
@securityrss.bsky.social
A respectable bake. You'd come back tomorrow for another.
Summary
Microsoft has patched a high-severity remote code execution vulnerability (CVE-2026-45659) in SharePoint that affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. The vulnerability stems from SharePoint deserializing untrusted data and can be exploited by an authenticated attacker to execute code remotely on a vulnerable SharePoint Server instance with low attack complexity and no user interaction required.
Key quotes
· 2 pulledCVE-2026-45659 stems from SharePoint deserializing untrusted data, and may be exploited by an authenticated attacker to execute code remotely on a vulnerable SharePoint Server instance – no user interaction required.
The attack complexity is Low (AC:L) because an attacker does not require any special conditions or mitigations to exploit the vulnerability.
You might also wanna read
Global Cyberattack Exploits Microsoft SharePoint Vulnerability, Targets Government Agencies and Businesses
Hackers exploited a major security vulnerability in Microsoft's SharePoint collaboration software to launch a global cyberattack targeting U
CVE-2025-53136: Microsoft Patches Windows Kernel Information Disclosure Vulnerability Bypassing KASLR
Microsoft patched CVE-2025-53136, a kernel information disclosure vulnerability in Windows NT OS Kernel that allowed leaking kernel base add
Critical React Vulnerability (CVE-2025-55182) Enables Remote Code Execution in React 19 and Next.js
A critical security vulnerability (CVE-2025-55182) has been discovered in React Server Components' 'Flight' protocol, affecting React 19 and
Microsoft 365 Copilot Vulnerability: Mermaid Diagram Attack Enables Data Exfiltration
A security researcher discovered a vulnerability in Microsoft 365 Copilot where specially crafted Office documents could trigger indirect pr
adamlogue.com·7mo agoCritical Security Vulnerability in React Server Components (CVE-2025-55182) Allows Remote Code Execution
The React team disclosed a critical security vulnerability (CVE-2025-55182) rated CVSS 10.0 that allows unauthenticated remote code executio
Critical Security Vulnerability CVE-2025-66478 in React Server Components Protocol
A critical security vulnerability (CVE-2025-66478) has been discovered in the React Server Components (RSC) protocol with a CVSS score of 10
