CVE-2026-45659CISA KEV
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
- Product
- SharePoint Server
- Added to KEV
- 1 Jul 2026
- Federal remediation due
- 4 Jul 2026
- Known ransomware use
- Yes