Microsoft told the world this bug was “less likely” to be exploited. Ransomware crews disagreed—and they had six weeks to prove it.
The Cybersecurity and Infrastructure Security Agency (CISA) has officially added SharePoint CVE-2026-45659 to its Known Exploited Vulnerabilities (KEV) catalog, confirming that attackers are actively using this remote code execution (RCE) flaw against real organizations right now. Federal civilian agencies were given an emergency 48-hour deadline to patch.
If your business runs on-premises SharePoint Server—or your Managed Service Provider (MSP) runs one for you—this is not a “get to it next sprint” item. It is an active emergency.
The Hidden Reality: Low Privileges, High Damage
Most IT executives assume a remote code execution flaw this serious requires admin access or a complex exploit chain. It doesn’t.
CVE-2026-45659 is a deserialization vulnerability with a massive CVSS score of 8.8, and the barrier to entry is shockingly low. Any authenticated user holding basic Site Member permissions—the default access level handed to almost every employee on any SharePoint farm—can trigger it.
No admin rights. No elevated privileges. No user interaction required on the victim’s end. An attacker just needs one valid set of low-level credentials—the kind that show up constantly in phishing kits and infostealer logs—and they can execute arbitrary code directly on your SharePoint server.
The Standard Advice (And Why It Backfires)
The obvious advice is: “Just apply the patch.” But in this scenario, patching alone creates a false sense of security.
Security researchers have tied active exploitation of this flaw to Storm-2603, a highly sophisticated threat actor with a track record of hitting on-premises servers to deploy Warlock ransomware. Once inside, attackers don’t just encrypt files. They build multiple remote access channels using legitimate tools (like Cloudflare tunneling and SSH), create new local domain administrator accounts, and disable endpoint security software entirely.
If you blindly apply the patch without hunting for persistence mechanisms, you are simply locking the front door while the attackers are already sitting in your living room.
The Edge Case: The Holiday Weekend Window
There is a dangerous pattern that security teams keep missing: ransomware crews time their deployments around reduced staffing.
As we saw with the recent 4th of July weekend ransomware spikes, groups like Storm-2603 have a documented history of hitting multiple victim environments simultaneously during holidays. Skeleton IT teams, delayed alert triage, and slow change-management approvals allow an intrusion to sit undetected for days.
If your organization assumed “we’ll patch it on Monday” was good enough, the attackers were counting on that assumption specifically.
The Emergency Audit Checklist
You need to take immediate, proactive steps. Run through this checklist to secure your SharePoint environment:
- Confirm Patch Status Across the Farm: Verify the May 2026 SharePoint security update is installed across every server in the farm. Multi-server environments often have inconsistent build versions.
- Audit Site Member Accounts: Review every account with Site Member or higher permissions, especially external or guest users. This is the exact privilege level attackers need to launch the exploit.
- Hunt for Indicators of Compromise (IoCs): Look for hidden webshells, unfamiliar scheduled tasks, new domain admin accounts, and unusual IIS worker process activity.
- Demand MSP Accountability: Just like with the recent SimpleHelp RMM vulnerability, if a third party manages your SharePoint environment, get written confirmation that CVE-2026-45659 has been patched and logs have been audited.
What Happens Next
This is not an isolated incident. It is the third SharePoint vulnerability confirmed under active exploitation in 2026 alone. The pattern is painfully clear: on-premises collaboration platforms are being systematically targeted, and the window between a patch release and real-world exploitation keeps shrinking.
Until organizations start treating internal collaboration platforms with the same intense scrutiny as public-facing web servers, this cycle of “patched but exploited anyway” will keep repeating.
Frequently Asked Questions
What exactly is SharePoint CVE-2026-45659?
It is a critical deserialization vulnerability in Microsoft SharePoint Server that lets an authenticated attacker with basic “Site Member” permissions execute arbitrary code remotely on the server, without needing admin rights.
Is my SharePoint Online (Microsoft 365) environment affected?
No. This flaw strictly affects on-premises SharePoint Server deployments (Subscription Edition, Server 2019, and Enterprise Server 2016). Cloud-hosted SharePoint Online is patched directly by Microsoft.
Why did Microsoft say exploitation was “less likely”?
Microsoft’s original severity assessment was made before real-world attack data existed. CISA’s KEV addition is based on confirmed evidence of active ransomware exploitation by groups like Storm-2603, which overrides the vendor’s earlier theoretical assessment.
For a complete tracker of all critical 2026 vulnerabilities, see our Enterprise CVE Security Hub.
Reported by CyberUpdates365 Desk
Delivering the latest insights on enterprise security, federal AI directives, and the future of IT infrastructure. Follow us for daily updates on how technology is reshaping the corporate landscape.




