Microsoft patched this vulnerability in May. It did not tell you it was being exploited until July.

CVE-2026-45659 — CVSS 8.8 — SharePoint Server remote code execution via deserialization of untrusted data — just landed on CISA's Known Exploited Vulnerabilities catalog. The patch has existed for two months. The active exploitation confirmation did not.

WHAT ACTUALLY HAPPENED

Microsoft shipped the fix in the May cycle and assessed exploitation as "less likely." CISA disagreed. Evidence of active attacks in the wild forced the KEV listing, with a hard remediation deadline of July 4 for federal civilian agencies.

That deadline has already passed.

An unauthenticated or low-privilege attacker sends crafted serialized data to a vulnerable SharePoint endpoint. The server deserializes it. Arbitrary code executes in the context of the SharePoint application pool. From there: document repositories, connected Active Directory, every downstream integration SharePoint touches.

WHY THE TIMELINE MATTERS MORE THAN THE CVSS SCORE

A "less likely to be exploited" label bought two months of reduced urgency across thousands of IT teams. Attackers did not read that label the same way. Vendor severity assessments are a starting point for prioritization, not a substitute for your own exposure analysis.

If your patch cadence runs on vendor-assigned exploitability ratings alone, this is the gap that closes on you.

WHAT TO DO NOW

CONFIRM THE MAY PATCH IS ACTUALLY DEPLOYED — do not assume the May cycle succeeded. Pull SharePoint farm version numbers directly.

HUNT FOR POST-EXPLOITATION ARTIFACTS — review IIS logs and SharePoint ULS logs for anomalous deserialization payloads and unexpected w3wp.exe child processes predating today's date.

ISOLATE INTERNET-FACING FARMS — any SharePoint instance reachable from the internet is higher priority than internal-only deployments.

STOP TRUSTING SEVERITY LABELS BLINDLY — track KEV catalog additions directly. A patch existing is not the same as a patch being urgent, until suddenly it is.

The gap between "patched" and "known exploited" was two months. Your exposure window was open the entire time.

Is your patch management process tracking CISA KEV additions, or just vendor advisories?
Turn the analysis into a plan

The gap between knowing the risk and closing it is a purchase order and a weekend.

We specify, source and deploy the equipment that closes it — firewalls, segmentation, secure remote access — and we support it afterwards.