What We Know
Multiple security outlets and vendor advisories report that CVE-2026-45659, a remote code execution vulnerability in Microsoft SharePoint Server, is being actively exploited in the wild. The Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog after evidence of exploitation, and several advisories urge immediate action to close the gap.
The reporting consistently directs on-premises SharePoint Server administrators to apply the May 2026 fixes or other available patches; several posts frame a federal patching deadline of July 4 for affected systems. Coverage emphasizes that attackers have already targeted the flaw and that organizations that have not applied the updates risk arbitrary code execution on exposed SharePoint servers. Guidance for administrators focuses on deploying Microsoft’s patches and checking SharePoint installations for exposure ahead of the deadline.
Source Comparison
Aligned reportingCorroborates
- decryptiondigest.com↗Reports CVE-2026-45659 as an actively exploited SharePoint RCE, cites CISA KEV, and urges administrators to patch before the July 4 deadline.
- BleepingComputer↗Confirms CISA warned attackers have begun exploiting SharePoint RCE CVE-2026-45659 and urges applying patches to mitigate arbitrary code execution risk.
- vulert.com↗States CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog after evidence of active exploitation and that it affects SharePoint Server.
- cloudkey-tech.com↗Says on-premises SharePoint Server is being exploited for arbitrary code execution via CVE-2026-45659 and frames a federal July 4 patching deadline, urging immediate application of fixes.
- vpncentral.com↗Reports CISA warned the SharePoint Server RCE CVE-2026-45659 is being exploited in the wild, notes the KEV listing, and recommends patching.
- thehackernews.com↗Confirms CVE-2026-45659 was added to CISA's KEV following active exploitation and stresses administrators should apply Microsoft's patches.
- scworld.com↗Reports that CISA added the SharePoint RCE CVE-2026-45659 to its Known Exploited Vulnerabilities list and supports urgent patching and vulnerability management guidance.