By Zeljka Zorz
Publication Date: 2026-05-26 10:44:00
Microsoft has released patches for a high-severity remote code execution vulnerability (CVE-2026-45659) in SharePoint that may be exploited in low-complexity attacks.
It affects the SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016.
About CVE-2026-45659
CVE-2026-45659 stems from Shareoint deserializing untrusted data, and may be exploited by an authenticated attacker to execute code remotely on a vulnerable SharePoint Server instance – no user interaction required.
“The attack complexity is Low (AC:L) because an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component,” Microsoft explained.
In order to exploit it, though, attackers must first successfully authenticate to the server.
SharePoint: A popular target
SharePoint servers are an attractive target for attackers as they often hold sensitive company data and are…



