Knox CVE Database
/
CVE-2026-45659
High
8.8
Ransomware use

CVE-2026-45659: Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.

Added to the CISA KEV catalog:
July 1, 2026

Overview

Microsoft SharePoint Server contains an unsafe deserialization flaw that allows an authenticated attacker to execute arbitrary code on the server over the network. Any SharePoint Server 2016, 2019, or Subscription Edition deployment reachable by an attacker with even a basic user account is at risk. This vulnerability is actively exploited and has been associated with ransomware campaigns, making unpatched internet-facing deployments a high-priority target.

Vulnerability details

Affected vendor
Microsoft
Affected product
SharePoint Server
Weakness type (CWE)
CWE-502

SharePoint Server fails to validate serialized data before processing it, a classic CWE-502 condition. When an application deserializes attacker-controlled objects without enforcing type safety or integrity checks, the deserialization process itself becomes a code execution primitive: the runtime instantiates and invokes methods on attacker-supplied objects before any application-level logic can inspect them. In SharePoint's case, the server accepts a crafted serialized payload from an authenticated network request and processes it without sufficient validation, triggering execution of attacker-controlled code during deserialization.


An attacker who holds any valid low-privilege SharePoint account can submit a crafted serialized payload to the server over the network. No additional user interaction or elevated permissions are required beyond that initial authenticated session. Successful exploitation yields remote code execution running under the SharePoint service process, giving the attacker full control over the confidentiality, integrity, and availability of the affected server. Given confirmed ransomware use in the wild, the realistic post-exploitation path includes credential harvesting, lateral movement, and data encryption or exfiltration.

Severity and impact

8.8
High
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Known

Detection and monitoring

  • Review SharePoint Unified Logging Service (ULS) logs and Windows Application event logs for unexpected process spawning from the SharePoint service account, particularly child processes such as cmd.exe, powershell.exe, or wscript.exe that have no corresponding scheduled job or administrative action.
  • Monitor for outbound network connections originating from the SharePoint service account or w3wp.exe worker processes to destinations outside the organization's normal SharePoint infrastructure, which may indicate post-exploitation callback activity.
  • Audit SharePoint server Windows Security event logs for new local account creation, privilege changes, or scheduled task registration occurring under the SharePoint service identity, which are common post-exploitation persistence steps.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
July 4, 2026

Additional hardening

  • Upgrade SharePoint Enterprise Server 2016 to build 16.0.5552.1002 or later, SharePoint Server 2019 to 16.0.10417.20128 or later, and SharePoint Server Subscription Edition to 16.0.19725.20280 or later. See the vendor advisory in References for the full patch matrix.
  • Restrict network access to SharePoint Server so that only known, authorized client IP ranges can reach it; internet-facing deployments with no network boundary controls are the highest-risk targets given confirmed ransomware exploitation.
  • Apply the principle of least privilege to SharePoint service accounts and disable or remove dormant user accounts to reduce the pool of valid credentials an attacker could use to satisfy the authentication precondition.
  • Conduct forensic triage per CISA guidance (see References) on any SharePoint Server that was internet-exposed before patching, focusing on ULS logs, Windows event logs, and file system changes under the SharePoint installation directories.

Key dates

Published (NVD)
May 22, 2026
Added to CISA KEV
July 1, 2026
Remediation deadline
July 4, 2026
Last updated
July 23, 2026

References

Frequently asked questions

Does CVE-2026-45659 affect my FedRAMP authorization?

If Microsoft SharePoint Server runs inside your authorization boundary, yes. CVE-2026-45659 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of July 4, 2026. For a FedRAMP-authorized service, an unpatched KEV within your boundary is an assessor finding. You must either remediate it or formally document a mitigation before your assessor and sponsoring agency raise it during review.

How does Knox help me handle CVE-2026-45659?

Knox does not patch your software. Remediating Microsoft SharePoint Server is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, along with continuous compliance monitoring and audit-artifact coverage to help you document the fix for your next assessment. The patch is yours to apply; maintaining a defensible compliance posture while you apply it is not something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including CVE-2026-45659. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving you the lead time to act before a finding becomes a formal problem.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-45659 isn't remediated by July 4, 2026?

Missing the July 4, 2026 deadline turns CVE-2026-45659 into a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what converts a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Meeting the deadline keeps your authorization clean and the agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting