Threat reportVulnerabilityTL-2026-0589

Microsoft SharePoint Authenticated RCE via Deserialization of Untrusted Data (CVE-2026-45659)

highPATCHED

Microsoft SharePoint Authenticated RCE via Deserialization (TL-2026-0589) is a high-severity software vulnerability scored CVSS 8.8, first published 2026-05-26. It has no confirmed attribution, affects Microsoft SharePoint Server Subscription Edition, references 1 CVE (CVE-2026-45659), maps to 26 MITRE ATT&CK techniques (T1003.001, T1021.002, T1027), and is covered by 9 detection rules and 16 indicators of compromise.

CVSS
8.8/10High
CVEs
1Referenced vulnerabilities
Techniques
26MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-0589

Threat ID
TL-2026-0589
Severity
HIGH
CVSS
8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
government, financial, healthcare, education, manufacturing, technology, legal, energy
Target regions
Global
Detection rules
9
Indicators of compromise
16

Malware and tooling in Microsoft SharePoint Authenticated RCE via Deserialization

Malware and tooling: ysoserial.net

How Microsoft SharePoint Authenticated RCE via Deserialization works

CVE-2026-45659 is a deserialization-of-untrusted-data vulnerability (CWE-502) in Microsoft Office SharePoint disclosed by Microsoft on 2026-05-22. An authenticated attacker with low-privilege Site Member rights can deliver a crafted serialized payload to a vulnerable SharePoint endpoint, triggering arbitrary code execution in the context of the SharePoint application pool identity (typically a privileged service account). CVSS 3.1 base score 8.8 (HIGH); Microsoft has shipped patches via the May 2026 MSRC release cycle.

Microsoft disclosed CVE-2026-45659 on 2026-05-22 as a network-exploitable authenticated remote code execution vulnerability affecting Microsoft Office SharePoint Server. The root cause is unsafe BinaryFormatter/LosFormatter/ObjectStateFormatter-style deserialization of attacker-controlled serialized .NET objects delivered through a SharePoint web endpoint. When the SharePoint Application Pool processes the crafted payload, gadget chains within the loaded assemblies (commonly TypeConfuseDelegate, ActivitySurrogateSelector, or System.Workflow.ComponentModel surrogates as seen in prior SharePoint deserialization issues) execute arbitrary code under the w3wp.exe worker process identity.

This vulnerability sits in the same family as the ToolShell exploit chain (CVE-2025-49706 / CVE-2025-49704 / CVE-2025-53770) that drove worldwide compromises of on-premise SharePoint farms in July 2025, as well as the older CVE-2020-1147 ViewState issue and CVE-2019-0604 picker validation flaw. The 2026-05-22 disclosure differs in that exploitation requires authentication (PR:L) — an attacker must hold at least SharePoint Site Member credentials — but the network-reachable attack surface (AV:N), low attack complexity (AC:L), and full confidentiality/integrity/availability impact (C:H/I:H/A:H) make it an attractive secondary-stage objective after credential theft, phishing, password spray, or session-cookie replay.

Exploit chain (expected, based on family precedent): (1) initial access — attacker harvests valid SharePoint user credentials via phishing/password-spray/cookie-replay or pivots from an already-compromised endpoint; (2) authentication to the target SharePoint web front end over HTTPS; (3) delivery of a crafted serialized .NET object — typically embedded in a request to a vulnerable handler such as the picker callback, web part property bag, ViewState, or list event receiver — using publicly available tooling such as ysoserial.net to produce TypeConfuseDelegate or other gadget chains targeting Microsoft.SharePoint.dll; (4) the application pool worker process deserializes the payload, instantiates the malicious object graph, and executes attacker code; (5) post-exploitation typically follows the ToolShell playbook — drop a small ASPX webshell (e.g., spinstall0.aspx) inside the LAYOUTS directory, extract the SharePoint MachineKey ValidationKey/DecryptionKey for persistent payload forging, enumerate site collections, dump content database connection strings, and pivot via Kerberos delegation or saved credentials. Threat actors known to have weaponised the prior SharePoint family include Linen Typhoon, Violet Typhoon, and Storm-2603 (Microsoft naming); historical actors with deep SharePoint deserialization tradecraft include APT41 and the Hafnium-adjacent clusters.

Indicator and detection priorities: w3wp.exe spawning cmd.exe / powershell.exe / csc.exe / cscript.exe; ASPX file writes to the LAYOUTS, _layouts, or TEMPLATE directories under the SharePoint hive; unusual base64 or gzip blobs in POST bodies to /_layouts/15/, /_layouts/16/, /_vti_bin/, or list/library endpoints; outbound TLS from SharePoint farms to non-Microsoft destinations; ASP.NET deserialization exceptions (event ID 1310) immediately preceded or followed by w3wp.exe child process creation; machine-key disclosure events (file reads on web.config from non-administrative processes).

Microsoft shipped patches via the May 2026 Patch Tuesday release. Organizations running SharePoint Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016 should apply the relevant security update KB, rotate the SharePoint MachineKey ValidationKey and DecryptionKey post-patch (the rotation is essential because attackers who reached an unpatched server can forge signed payloads indefinitely without it), restart IIS, and audit for the post-exploitation indicators above. On-premise SharePoint farms exposed directly to the internet should be prioritised; defenders should also restrict SharePoint authentication to corporate identity providers with MFA and revoke service-principal/long-lived tokens.

MITRE ATT&CK techniques used in TL-2026-0589

Credential Access

T1003.001 OS Credential Dumping: LSASS Memory; T1552.001 Unsecured Credentials: Credentials In Files; T1606 Forge Web Credentials

Lateral Movement

T1021.002 Remote Services: SMB/Windows Admin Shares; T1550 Use Alternate Authentication Material

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1070.004 Indicator Removal: File Deletion

Exfiltration

T1041 Exfiltration Over C2 Channel

Privilege Escalation

T1055 Process Injection; T1068 Exploitation for Privilege Escalation

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1106 Native API

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer

Initial Access

T1078 Valid Accounts; T1078.002 Valid Accounts: Domain Accounts; T1190 Exploit Public-Facing Application; T1566 Phishing

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery; T1087.002 Account Discovery: Domain Account

Persistence

T1098 Account Manipulation; T1505.003 Server Software Component: Web Shell

Collection

T1213.002 Data from Information Repositories: SharePoint

Affected products and versions in Microsoft SharePoint Authenticated RCE via Deserialization

  • Microsoft — SharePoint Server Subscription Edition
    Vulnerable versions: all builds prior to May 2026 security update
    Fixed in: May 2026 cumulative security update
  • Microsoft — SharePoint Server 2019
    Vulnerable versions: all builds prior to May 2026 security update
    Fixed in: May 2026 cumulative security update
  • Microsoft — SharePoint Server 2016
    Vulnerable versions: all builds prior to May 2026 security update
    Fixed in: May 2026 cumulative security update

Remediation for Microsoft SharePoint Authenticated RCE via Deserialization

Patches

  • Microsoft Security Update for CVE-2026-45659 — SharePoint Subscription Edition (May 2026 MSRC release)
  • Microsoft Security Update for CVE-2026-45659 — SharePoint Server 2019 (May 2026 MSRC release)
  • Microsoft Security Update for CVE-2026-45659 — SharePoint Server 2016 (May 2026 MSRC release)

Immediate actions

  • Apply Microsoft May 2026 security updates for SharePoint Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016 (KBs published in MSRC update guide for CVE-2026-45659)
  • Rotate SharePoint MachineKey ValidationKey and DecryptionKey on every web front end after patching (Set-SPMachineKey / Update-SPMachineKey or manual web.config rotation) and restart IIS — this is essential to revoke any previously forged payloads
  • Audit LAYOUTS / _layouts / TEMPLATE directories for unexpected ASPX, ASMX, or ASHX files (especially spinstall0.aspx, spinstall1.aspx, debug_dev.js, ghostfile.aspx) and quarantine for forensic review
  • Block direct internet exposure of on-premise SharePoint web front ends; place behind an authenticated reverse proxy with MFA enforcement
  • Revoke and reissue SharePoint service account credentials and any OAuth/long-lived tokens that may have been disclosed via web.config or LSASS scraping

Workarounds

  • Until patches can be staged, disable anonymous and self-service site creation, restrict SharePoint Site Member assignment to vetted identities only, and remove guest/external sharing on sensitive site collections
  • Front SharePoint with a Web Application Firewall configured to block requests containing serialized .NET marker strings (e.g., AAEAAAD/////, ObjectStateFormatter signatures, base64-encoded TypeConfuseDelegate patterns)
  • Enforce IP allow-listing on the SharePoint web front end so authentication endpoints are only reachable from corporate networks and VPN ranges

Longer-term hardening

  • Deploy Microsoft Defender for Endpoint with attack surface reduction rule 'Block Office applications from creating child processes' equivalent enforced on SharePoint hosts via WDAC/AppLocker for w3wp.exe child processes
  • Enable SharePoint Antimalware Scan Interface (AMSI) integration and ensure Defender Antivirus is in active mode on every farm host
  • Migrate eligible workloads from on-premise SharePoint to SharePoint Online / Microsoft 365 where Microsoft assumes deserialization-attack-surface management
  • Implement network segmentation isolating SharePoint farms from domain controllers, file servers, and SQL backends; restrict outbound internet egress to a documented allow list
  • Roll out detection content for ASP.NET deserialization exceptions (Application event ID 1310) correlated with w3wp.exe process tree anomalies
  • Centralise SharePoint authentication via ADFS / Entra ID with conditional access policies that require MFA and compliant device posture for any account capable of authoring SharePoint content

CVEs associated with Microsoft SharePoint Authenticated RCE via Deserialization

CVE-2026-45659

Weaknesses (CWE) in Microsoft SharePoint Authenticated RCE via Deserialization

CWE-502

Timeline of Microsoft SharePoint Authenticated RCE via Deserialization

  • Microsoft patches an early .NET deserialization RCE in Workflow components, establishing the gadget-chain pattern later abused against SharePoint.
  • CVE-2019-0604 (SharePoint picker callback deserialization) is patched after widespread exploitation, including by APT actors against the United Nations and aid organizations.
  • CVE-2020-1147 (.NET ViewState DataSet/DataTable deserialization) is patched; SharePoint surfaces are confirmed exploitable.
  • ToolShell exploit chain (CVE-2025-49706 / CVE-2025-49704 / CVE-2025-53770) is observed in active mass exploitation against on-premise SharePoint farms; CISA issues emergency guidance.
  • NVD publishes CVE-2026-45659 with CVSS 3.1 vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
  • Microsoft publishes CVE-2026-45659 in the MSRC update guide as an authenticated deserialization RCE in SharePoint with CVSS 8.8 HIGH; security updates shipped concurrently.
  • Threadlinqs Intelligence opens tracking TL-2026-0589 based on CISA/NVD feed monitoring and SharePoint deserialization family precedent.
  • As of 2026-05-29, CVE-2026-45659 (SharePoint authenticated deserialization RCE, CVSS 8.8) was fixed in Microsoft's May 2026 updates; Microsoft rates it "less likely to be exploited," with no public PoC, no in-the-wild exploitation, and no CISA KEV listing. Patched and not exploited; risk persists only for unpatched on-prem farms given the ToolShell deserialization lineage.

Sources cited for Microsoft SharePoint Authenticated RCE via Deserialization

Detection coverage for TL-2026-0589

As of 2026-05-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0589 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats