CISA Warns of Active Exploitation Targeting Microsoft SharePoint RCE Flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that attackers are actively exploiting a high-severity remote code execution vulnerability in Microsoft SharePoint. Tracked as CVE-2026-45659, the flaw stems from improper deserialization of untrusted data and allows authenticated attackers with low privileges to execute arbitrary code on unpatched servers. Microsoft notes that the attack requires no user interaction and poses low complexity for threat actors.
Microsoft released security updates for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition on May 21 to address the issue. However, the vulnerability was accidentally omitted from the May 2026 Patch Tuesday release, potentially leaving many organizations unaware of the risk. Internet security monitoring group Shadowserver currently tracks over 10,000 SharePoint servers exposed online, though it remains unclear how many have already been secured.
CISA adds the vulnerability to its Known Exploited Vulnerabilities Catalog and orders federal agencies to patch their systems by Saturday under Binding Operational Directive 26-04. This directive requires agencies to prioritize patching based on factors such as active exploitation, automation potential, public exposure, and the level of system control an attacker can achieve. Simmons Systems advises all organizations running affected SharePoint versions to apply patches immediately and reduce internet exposure where possible.