Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
Microsoft SharePoint Server contains an unsafe deserialization flaw that allows an authenticated attacker to execute arbitrary code on the server over the network. Any SharePoint Server 2016, 2019, or Subscription Edition deployment reachable by an attacker with even a basic user account is at risk. This vulnerability is actively exploited and has been associated with ransomware campaigns, making unpatched internet-facing deployments a high-priority target.
SharePoint Server fails to validate serialized data before processing it, a classic CWE-502 condition. When an application deserializes attacker-controlled objects without enforcing type safety or integrity checks, the deserialization process itself becomes a code execution primitive: the runtime instantiates and invokes methods on attacker-supplied objects before any application-level logic can inspect them. In SharePoint's case, the server accepts a crafted serialized payload from an authenticated network request and processes it without sufficient validation, triggering execution of attacker-controlled code during deserialization.
An attacker who holds any valid low-privilege SharePoint account can submit a crafted serialized payload to the server over the network. No additional user interaction or elevated permissions are required beyond that initial authenticated session. Successful exploitation yields remote code execution running under the SharePoint service process, giving the attacker full control over the confidentiality, integrity, and availability of the affected server. Given confirmed ransomware use in the wild, the realistic post-exploitation path includes credential harvesting, lateral movement, and data encryption or exfiltration.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If Microsoft SharePoint Server runs inside your authorization boundary, yes. CVE-2026-45659 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of July 4, 2026. For a FedRAMP-authorized service, an unpatched KEV within your boundary is an assessor finding. You must either remediate it or formally document a mitigation before your assessor and sponsoring agency raise it during review.
Knox does not patch your software. Remediating Microsoft SharePoint Server is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, along with continuous compliance monitoring and audit-artifact coverage to help you document the fix for your next assessment. The patch is yours to apply; maintaining a defensible compliance posture while you apply it is not something you manage alone.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including CVE-2026-45659. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving you the lead time to act before a finding becomes a formal problem.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
Missing the July 4, 2026 deadline turns CVE-2026-45659 into a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what converts a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Meeting the deadline keeps your authorization clean and the agency relationship intact.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.











_Horizontal_RGB.png)









