Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5415 articles · 192779 vulns · 37/41 feeds (7d)
← Back to list
8.8
CVE-2026-45659KEVEXPLOITEDPATCHED
microsoft · sharepoint_server

Microsoft SharePoint Remote Code Execution Vulnerability

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Affected Products

VendorProductVersions
microsoftsharepoint_server16.0.0, 16.0.0, 16.0.0

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659(vendor-advisory, patch)

Related News (16 articles)

Tier D
BleepingComputer4h ago
CISA: Windows Task Host flaw now exploited by ransomware gangs
→ No new info (linked only)
Tier D
BleepingComputer6d ago
Hackers leverage new Microsoft SharePoint exploit in attacks
→ No new info (linked only)
Tier D
BleepingComputer7d ago
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
→ No new info (linked only)
Tier D
CSO Online33d ago
CISA urges immediate SharePoint hardening as exploits mount
→ No new info (linked only)
Tier D
BleepingComputer34d ago
CISA warns admins to patch actively exploited SharePoint flaws
→ No new info (linked only)
Tier B
CCCS Canada47d ago
AL26-015 - Critical vulnerability impacting Microsoft SharePoint Server – CVE-2026-45659
→ No new info (linked only)
Tier D
BleepingComputer47d ago
CISA: Microsoft SharePoint RCE flaw now actively exploited
→ No new info (linked only)
Tier D
SecurityWeek47d ago
CISA Warns of Actively Exploited Microsoft SharePoint Vulnerability
→ No new info (linked only)
Tier D
The Hacker News47d ago
SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
→ No new info (linked only)
Tier D
Help Net Security74d ago
June 2026 Patch Tuesday forecast: Where are the CVEs?
→ No new info (linked only)
Tier A
Microsoft MSRC84d ago
CVE-2026-45659 Microsoft SharePoint Remote Code Execution Vulnerability
→ No new info (linked only)
Tier D
The Hacker News84d ago
Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions
→ No new info (linked only)
Tier D
Help Net Security84d ago
High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659)
→ No new info (linked only)
Tier C
VulDB87d ago
CVE-2026-45659 | Microsoft SharePoint Enterprise Server deserialization
→ No new info (linked only)
Tier B
BSI Advisories88d ago
[NEU] [hoch] Microsoft SharePoint Server 2016 und SharePoint Server 2019: Schwachstelle ermöglicht Codeausführung
→ No new info (linked only)
Tier B
CERT-FR88d ago
Vulnérabilité dans les produits Microsoft (22 mai 2026)
→ No new info (linked only)
CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
16.0.5552.1002
CWECWE-502
PublishedMay 22, 2026
Last enriched33d agov9
Tags
CISA KEVCVE-2026-45659CISA KEV - CVE-2026-56164elevation-of-privilegeunauthenticated remote exploitationremote exploitation without authenticationinsecure deserializationimproper input validation
Trending Score155🔥
Source articles16
Independent10
Info Completeness12/14
Missing: epss, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-55040EXPKEV
Microsoft SharePoint Server Security Feature Bypass Vulnerability
Trending: 132
HIGHCVE-2026-68820EXPKEV
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Trending: 127
HIGHCVE-2026-63520
Microsoft SharePoint Server Remote Code Execution Vulnerability
Trending: 62
HIGHCVE-2026-69414
Microsoft Defender Elevation of Privilege Vulnerability
Trending: 56
HIGHCVE-2026-32193
Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability
Trending: 56

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 22, 2026
Added to CISA KEV
May 22, 2026
Discovered by ZDM
May 22, 2026
Updated: description, severity
May 23, 2026
Updated: affectedVersions
May 26, 2026
Updated: exploitAvailable, tags
Jul 2, 2026
Updated: description, affectedVersions
Jul 2, 2026
Updated: description, cweIds, patchAvailable, tags
Jul 2, 2026
Updated: affectedVersions, patchAvailable
Jul 2, 2026
Updated: affectedVersions, cweIds, tags
Jul 16, 2026
Updated: severity, cvssEstimate, mitreAttack, tags
Jul 16, 2026
Actively Exploited
Aug 11, 2026
Exploit Available
Aug 11, 2026
Patch Available
Aug 11, 2026

Version History

v9
Last enriched 33d ago
v9Tier D33d ago

Updated CVE-2026-56164 severity to CRITICAL due to active wild exploitation despite lower CVSS 5.3 score, corrected CVSS from 8.8 to 5.3 for CVE-2026-56164, added MITRE ATT&CK T1190 (Exploit Public-Facing Application), and clarified that CVE-2026-56164 can be exploited remotely without authentication making it significantly more dangerous than severity rating suggests.

severitycvssEstimatemitreAttacktags
via CSO Online
v8Tier D33d ago

Article introduces newly exploited vulnerability CVE-2026-56164 (elevation-of-privilege, CVSS 5.3, remotely exploitable without authentication) confirmed in CISA KEV catalog; added CWE-269 and MITRE T1548 technique for privilege escalation attacks.

affectedVersionscweIdstags
via CSO Online
v7Tier B46d ago

Updated affected versions with specific fixed version numbers and added CISA KEV tag.

affectedVersionspatchAvailable
via CCCS Canada
v6Tier D47d ago

Updated description with technical details, added CVE-2026-45659 to tags, and noted the patch was released in late May.

descriptioncweIdspatchAvailabletags
via SecurityWeek
v5Tier D47d ago

Updated description with more technical detail, added affected versions, and confirmed severity and CVSS score.

descriptionaffectedVersions
via BleepingComputer
v4Tier D47d ago

Updated exploit availability to true, added CISA KEV tag, and confirmed CVSS score as 8.8.

exploitAvailabletags
via The Hacker News
v3Tier D84d ago

Updated description with technical details, added affected versions, changed severity to HIGH, updated CVSS estimate to 7.5, and marked exploit as available and actively exploited.

affectedVersions
via Help Net Security
v2Tier C87d ago

Updated severity to CRITICAL, changed description to include new details, and noted that no exploit is available.

descriptionseverity
via VulDB
v187d ago

Initial creation