LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-45659: Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 1, 2026
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jul 4, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog on Jul 1, 2026, with a federal patch deadline of Jul 4, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.

This vulnerability affects Microsoft SharePoint Server and involves deserialization of untrusted data. An authorized attacker can execute code over a network. It matters because the flaw resides in a widely deployed collaboration platform that often holds internal documents and connects to broader enterprise networks.

How it works

The weakness is categorized under CWE-502. The server accepts serialized data from an authenticated user and deserializes it without sufficient validation, allowing the resulting object graph to trigger code execution.

Exact data formats, required permissions, or network paths must be confirmed against the vendor advisory rather than assumed from the class description.

Am I affected? How to find it in your systems

Microsoft SharePoint Server is typically deployed on-premises as part of intranet or document-management infrastructure. Inventory all SharePoint Server installations through configuration management databases, server asset lists, or PowerShell queries against farm members.

How to remediate

Apply the vendor update referenced in the advisory as the primary step. Follow CISA BOD 26-04 guidance when prioritizing the deployment across internet-exposed or high-value assets.

If you can't patch immediately

Place SharePoint servers behind network segmentation that restricts inbound traffic to only necessary management and client subnets. Disable or restrict any web parts, web services, or custom code paths that accept serialized input until the update is applied.

If your data may have been exposed

Actively exploited vulnerabilities lead to breaches. Readers can run a free exposure scan of their email to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · SharePoint Server
WeaknessCWE-502
Added to CISA KEVJul 1, 2026
Federal patch deadlineJul 4, 2026
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities