CISA Just Gave Federal Agencies Until July 4 to Patch This SharePoint Flaw. Your Org Should Move Just as Fast.

CVE-2026-45659 — a remote code execution vulnerability in SharePoint Server — was just added to CISA's Known Exploited Vulnerabilities catalog. Translation: this isn't theoretical anymore. It's being actively exploited, right now, in the wild.


What's Actually Broken

The vulnerability stems from deserialization of untrusted data — a classic but still devastating flaw class. An attacker who can reach a vulnerable SharePoint Server can get remote code execution without needing valid credentials first.

SharePoint sits at the center of how most enterprises share documents, manage intranets, and connect Microsoft 365 workflows. A single compromised server often means direct access to internal file shares, authentication tokens, and lateral movement paths into the rest of the domain — including systems that were never supposed to be internet-facing in the first place.


Why the KEV Listing Matters More Than the CVE Score

CISA doesn't add vulnerabilities to the KEV catalog on theoretical risk. It adds them when there's confirmed evidence of active exploitation. That listing comes with a binding deadline for U.S. federal agencies — patch by July 4, 2026, or be in violation of Binding Operational Directive requirements.

For everyone outside the federal government, that deadline isn't legally binding. But the underlying fact is: real attackers are already using this. The clock that matters isn't the compliance deadline — it's the gap between "exploit is public" and "your server gets hit."


What To Do Right Now

- Patch immediately. Don't wait for a change window if the server is internet-facing. - Check server logs for signs of pre-patch exploitation — patching doesn't undo an existing compromise. - Isolate SharePoint servers that can't be patched immediately behind stricter network segmentation. - Rotate credentials and machine keys if you suspect any exposure window. - Assume this won't be the last SharePoint RCE this year — deserialization bugs in enterprise collaboration platforms keep resurfacing because the underlying architecture keeps getting reused.


My Take

KEV listings are one of the few genuinely useful signals in the vulnerability noise. When CISA lists something, it's not "patch when convenient" — it's "attackers are already inside similar environments."

If SharePoint Server is anywhere in your environment, this is this week's priority, not next sprint's backlog item.

Has your team already patched, or is this news to you?
Turn the analysis into a plan

The gap between knowing the risk and closing it is a purchase order and a weekend.

We specify, source and deploy the equipment that closes it — firewalls, segmentation, secure remote access — and we support it afterwards.