Threat reportVulnerabilityTL-2026-0589
Microsoft SharePoint Authenticated RCE via Deserialization of Untrusted Data (CVE-2026-45659)
Microsoft SharePoint Authenticated RCE via Deserialization (TL-2026-0589) is a high-severity software vulnerability scored CVSS 8.8, first published 2026-05-26. It has no confirmed attribution, affects Microsoft SharePoint Server Subscription Edition, references 1 CVE (CVE-2026-45659), maps to 26 MITRE ATT&CK techniques (T1003.001, T1021.002, T1027), and is covered by 9 detection rules and 16 indicators of compromise.
- CVSS
- 8.8/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 26MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 16Indicators of compromise
Key facts for TL-2026-0589
- Threat ID
- TL-2026-0589
- Severity
- HIGH
- CVSS
- 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- government, financial, healthcare, education, manufacturing, technology, legal, energy
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in Microsoft SharePoint Authenticated RCE via Deserialization
Malware and tooling: ysoserial.net
How Microsoft SharePoint Authenticated RCE via Deserialization works
CVE-2026-45659 is a deserialization-of-untrusted-data vulnerability (CWE-502) in Microsoft Office SharePoint disclosed by Microsoft on 2026-05-22. An authenticated attacker with low-privilege Site Member rights can deliver a crafted serialized payload to a vulnerable SharePoint endpoint, triggering arbitrary code execution in the context of the SharePoint application pool identity (typically a privileged service account). CVSS 3.1 base score 8.8 (HIGH); Microsoft has shipped patches via the May 2026 MSRC release cycle.
Microsoft disclosed CVE-2026-45659 on 2026-05-22 as a network-exploitable authenticated remote code execution vulnerability affecting Microsoft Office SharePoint Server. The root cause is unsafe BinaryFormatter/LosFormatter/ObjectStateFormatter-style deserialization of attacker-controlled serialized .NET objects delivered through a SharePoint web endpoint. When the SharePoint Application Pool processes the crafted payload, gadget chains within the loaded assemblies (commonly TypeConfuseDelegate, ActivitySurrogateSelector, or System.Workflow.ComponentModel surrogates as seen in prior SharePoint deserialization issues) execute arbitrary code under the w3wp.exe worker process identity.
This vulnerability sits in the same family as the ToolShell exploit chain (CVE-2025-49706 / CVE-2025-49704 / CVE-2025-53770) that drove worldwide compromises of on-premise SharePoint farms in July 2025, as well as the older CVE-2020-1147 ViewState issue and CVE-2019-0604 picker validation flaw. The 2026-05-22 disclosure differs in that exploitation requires authentication (PR:L) — an attacker must hold at least SharePoint Site Member credentials — but the network-reachable attack surface (AV:N), low attack complexity (AC:L), and full confidentiality/integrity/availability impact (C:H/I:H/A:H) make it an attractive secondary-stage objective after credential theft, phishing, password spray, or session-cookie replay.
Exploit chain (expected, based on family precedent): (1) initial access — attacker harvests valid SharePoint user credentials via phishing/password-spray/cookie-replay or pivots from an already-compromised endpoint; (2) authentication to the target SharePoint web front end over HTTPS; (3) delivery of a crafted serialized .NET object — typically embedded in a request to a vulnerable handler such as the picker callback, web part property bag, ViewState, or list event receiver — using publicly available tooling such as ysoserial.net to produce TypeConfuseDelegate or other gadget chains targeting Microsoft.SharePoint.dll; (4) the application pool worker process deserializes the payload, instantiates the malicious object graph, and executes attacker code; (5) post-exploitation typically follows the ToolShell playbook — drop a small ASPX webshell (e.g., spinstall0.aspx) inside the LAYOUTS directory, extract the SharePoint MachineKey ValidationKey/DecryptionKey for persistent payload forging, enumerate site collections, dump content database connection strings, and pivot via Kerberos delegation or saved credentials. Threat actors known to have weaponised the prior SharePoint family include Linen Typhoon, Violet Typhoon, and Storm-2603 (Microsoft naming); historical actors with deep SharePoint deserialization tradecraft include APT41 and the Hafnium-adjacent clusters.
Indicator and detection priorities: w3wp.exe spawning cmd.exe / powershell.exe / csc.exe / cscript.exe; ASPX file writes to the LAYOUTS, _layouts, or TEMPLATE directories under the SharePoint hive; unusual base64 or gzip blobs in POST bodies to /_layouts/15/, /_layouts/16/, /_vti_bin/, or list/library endpoints; outbound TLS from SharePoint farms to non-Microsoft destinations; ASP.NET deserialization exceptions (event ID 1310) immediately preceded or followed by w3wp.exe child process creation; machine-key disclosure events (file reads on web.config from non-administrative processes).
Microsoft shipped patches via the May 2026 Patch Tuesday release. Organizations running SharePoint Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016 should apply the relevant security update KB, rotate the SharePoint MachineKey ValidationKey and DecryptionKey post-patch (the rotation is essential because attackers who reached an unpatched server can forge signed payloads indefinitely without it), restart IIS, and audit for the post-exploitation indicators above. On-premise SharePoint farms exposed directly to the internet should be prioritised; defenders should also restrict SharePoint authentication to corporate identity providers with MFA and revoke service-principal/long-lived tokens.
MITRE ATT&CK techniques used in TL-2026-0589
Credential Access
T1003.001 OS Credential Dumping: LSASS Memory; T1552.001 Unsecured Credentials: Credentials In Files; T1606 Forge Web Credentials
Lateral Movement
T1021.002 Remote Services: SMB/Windows Admin Shares; T1550 Use Alternate Authentication Material
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1070.004 Indicator Removal: File Deletion
Exfiltration
T1041 Exfiltration Over C2 Channel
Privilege Escalation
T1055 Process Injection; T1068 Exploitation for Privilege Escalation
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1106 Native API
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer
Initial Access
T1078 Valid Accounts; T1078.002 Valid Accounts: Domain Accounts; T1190 Exploit Public-Facing Application; T1566 Phishing
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery; T1087.002 Account Discovery: Domain Account
Persistence
T1098 Account Manipulation; T1505.003 Server Software Component: Web Shell
Collection
Affected products and versions in Microsoft SharePoint Authenticated RCE via Deserialization
- Microsoft — SharePoint Server Subscription Edition
Vulnerable versions: all builds prior to May 2026 security update
Fixed in: May 2026 cumulative security update - Microsoft — SharePoint Server 2019
Vulnerable versions: all builds prior to May 2026 security update
Fixed in: May 2026 cumulative security update - Microsoft — SharePoint Server 2016
Vulnerable versions: all builds prior to May 2026 security update
Fixed in: May 2026 cumulative security update
Remediation for Microsoft SharePoint Authenticated RCE via Deserialization
Patches
- Microsoft Security Update for CVE-2026-45659 — SharePoint Subscription Edition (May 2026 MSRC release)
- Microsoft Security Update for CVE-2026-45659 — SharePoint Server 2019 (May 2026 MSRC release)
- Microsoft Security Update for CVE-2026-45659 — SharePoint Server 2016 (May 2026 MSRC release)
Immediate actions
- Apply Microsoft May 2026 security updates for SharePoint Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016 (KBs published in MSRC update guide for CVE-2026-45659)
- Rotate SharePoint MachineKey ValidationKey and DecryptionKey on every web front end after patching (Set-SPMachineKey / Update-SPMachineKey or manual web.config rotation) and restart IIS — this is essential to revoke any previously forged payloads
- Audit LAYOUTS / _layouts / TEMPLATE directories for unexpected ASPX, ASMX, or ASHX files (especially spinstall0.aspx, spinstall1.aspx, debug_dev.js, ghostfile.aspx) and quarantine for forensic review
- Block direct internet exposure of on-premise SharePoint web front ends; place behind an authenticated reverse proxy with MFA enforcement
- Revoke and reissue SharePoint service account credentials and any OAuth/long-lived tokens that may have been disclosed via web.config or LSASS scraping
Workarounds
- Until patches can be staged, disable anonymous and self-service site creation, restrict SharePoint Site Member assignment to vetted identities only, and remove guest/external sharing on sensitive site collections
- Front SharePoint with a Web Application Firewall configured to block requests containing serialized .NET marker strings (e.g., AAEAAAD/////, ObjectStateFormatter signatures, base64-encoded TypeConfuseDelegate patterns)
- Enforce IP allow-listing on the SharePoint web front end so authentication endpoints are only reachable from corporate networks and VPN ranges
Longer-term hardening
- Deploy Microsoft Defender for Endpoint with attack surface reduction rule 'Block Office applications from creating child processes' equivalent enforced on SharePoint hosts via WDAC/AppLocker for w3wp.exe child processes
- Enable SharePoint Antimalware Scan Interface (AMSI) integration and ensure Defender Antivirus is in active mode on every farm host
- Migrate eligible workloads from on-premise SharePoint to SharePoint Online / Microsoft 365 where Microsoft assumes deserialization-attack-surface management
- Implement network segmentation isolating SharePoint farms from domain controllers, file servers, and SQL backends; restrict outbound internet egress to a documented allow list
- Roll out detection content for ASP.NET deserialization exceptions (Application event ID 1310) correlated with w3wp.exe process tree anomalies
- Centralise SharePoint authentication via ADFS / Entra ID with conditional access policies that require MFA and compliant device posture for any account capable of authoring SharePoint content
CVEs associated with Microsoft SharePoint Authenticated RCE via Deserialization
Weaknesses (CWE) in Microsoft SharePoint Authenticated RCE via Deserialization
Timeline of Microsoft SharePoint Authenticated RCE via Deserialization
- Microsoft patches an early .NET deserialization RCE in Workflow components, establishing the gadget-chain pattern later abused against SharePoint.
- CVE-2019-0604 (SharePoint picker callback deserialization) is patched after widespread exploitation, including by APT actors against the United Nations and aid organizations.
- CVE-2020-1147 (.NET ViewState DataSet/DataTable deserialization) is patched; SharePoint surfaces are confirmed exploitable.
- ToolShell exploit chain (CVE-2025-49706 / CVE-2025-49704 / CVE-2025-53770) is observed in active mass exploitation against on-premise SharePoint farms; CISA issues emergency guidance.
- NVD publishes CVE-2026-45659 with CVSS 3.1 vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
- Microsoft publishes CVE-2026-45659 in the MSRC update guide as an authenticated deserialization RCE in SharePoint with CVSS 8.8 HIGH; security updates shipped concurrently.
- Threadlinqs Intelligence opens tracking TL-2026-0589 based on CISA/NVD feed monitoring and SharePoint deserialization family precedent.
- As of 2026-05-29, CVE-2026-45659 (SharePoint authenticated deserialization RCE, CVSS 8.8) was fixed in Microsoft's May 2026 updates; Microsoft rates it "less likely to be exploited," with no public PoC, no in-the-wild exploitation, and no CISA KEV listing. Patched and not exploited; risk persists only for unpatched on-prem farms given the ToolShell deserialization lineage.
Sources cited for Microsoft SharePoint Authenticated RCE via Deserialization
- NVD - CVE-2026-45659 Detail
- MSRC Security Update Guide - CVE-2026-45659
- MITRE CWE-502: Deserialization of Untrusted Data
- Microsoft - Disrupting active exploitation of on-premises SharePoint vulnerabilities (ToolShell precedent)
- CISA Alert - Active Exploitation of Microsoft SharePoint Vulnerabilities (ToolShell)
- ysoserial.net - .NET deserialization gadget chain generator
- MITRE ATT&CK T1190 - Exploit Public-Facing Application
- MITRE ATT&CK T1505.003 - Server Software Component: Web Shell
Detection coverage for TL-2026-0589
As of 2026-05-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0589 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.