Microsoft releases critical security patch for SharePoint deserialization vulnerability
By
Dirk Knop
Lightly toasted, lightly seasoned, mostly correct.
Summary
Microsoft has released May updates for SharePoint servers that patch a highly critical security vulnerability (CVE-2026-45659, CVSS 8.8). The flaw involves deserialization of untrusted data, allowing authenticated attackers to inject and execute malicious code over the network. Admins are urged to verify the updates are installed.
Key quotes
· 4 pulledAdmins running Microsoft SharePoint servers in their infrastructure should check if they have installed the May updates.
Microsoft is thus closing a security vulnerability classified as highly critical, which allows attackers to inject and execute malicious code.
The problem exists due to the deserialization of untrusted data, i.e., its unpacking and processing or even execution.
Attackers logged into SharePoint can thus smuggle code over the network (CVE-2026-45659, CVSS 8.8, Risk
You might also wanna read
Global Cyberattack Exploits Microsoft SharePoint Vulnerability, Targets Government Agencies and Businesses
Hackers exploited a major security vulnerability in Microsoft's SharePoint collaboration software to launch a global cyberattack targeting U
CVE-2025-53136: Microsoft Patches Windows Kernel Information Disclosure Vulnerability Bypassing KASLR
Microsoft patched CVE-2025-53136, a kernel information disclosure vulnerability in Windows NT OS Kernel that allowed leaking kernel base add
Microsoft 365 Copilot Vulnerability: Mermaid Diagram Attack Enables Data Exfiltration
A security researcher discovered a vulnerability in Microsoft 365 Copilot where specially crafted Office documents could trigger indirect pr
adamlogue.com·7mo agoForeign Hackers Breach US Nuclear Weapons Plant Through SharePoint Vulnerabilities
Foreign hackers successfully breached the Kansas City National Security Campus (KCNSC), a critical nuclear weapons manufacturing facility, b
Critical React Vulnerability (CVE-2025-55182) Enables Remote Code Execution in React 19 and Next.js
A critical security vulnerability (CVE-2025-55182) has been discovered in React Server Components' 'Flight' protocol, affecting React 19 and
Analysis of Critical .NET Vulnerability CVE-2025-55315: HTTP Request Smuggling Explained
This article provides an in-depth technical analysis of CVE-2025-55315, a critical .NET vulnerability with a CVSS score of 9.9. The author e
