# Microsoft SharePoint Authenticated RCE via Deserialization of Untrusted Data (CVE-2026-45659)

> CVE-2026-45659 is a deserialization-of-untrusted-data vulnerability (CWE-502) in Microsoft Office SharePoint disclosed by Microsoft on 2026-05-22. An authenticated attacker with low-privilege Site Member rights can deliver a crafted serialized payload to a vulnerable SharePoint endpoint, triggering arbitrary code execution in the context of the SharePoint application pool identity (typically a privileged service account). CVSS 3.1 base score 8.8 (HIGH); Microsoft has shipped patches via the May 2026 MSRC release cycle.

- **Published:** 2026-05-26T00:00:00Z
- **Last reviewed:** 2026-05-26T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0589
- **ID:** TL-2026-0589
- **Severity:** HIGH (CVSS 8.8)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-45659

## Description

Microsoft disclosed CVE-2026-45659 on 2026-05-22 as a network-exploitable authenticated remote code execution vulnerability affecting Microsoft Office SharePoint Server. The root cause is unsafe BinaryFormatter/LosFormatter/ObjectStateFormatter-style deserialization of attacker-controlled serialized .NET objects delivered through a SharePoint web endpoint. When the SharePoint Application Pool processes the crafted payload, gadget chains within the loaded assemblies (commonly TypeConfuseDelegate, ActivitySurrogateSelector, or System.Workflow.ComponentModel surrogates as seen in prior SharePoint deserialization issues) execute arbitrary code under the w3wp.exe worker process identity.

This vulnerability sits in the same family as the ToolShell exploit chain (CVE-2025-49706 / CVE-2025-49704 / CVE-2025-53770) that drove worldwide compromises of on-premise SharePoint farms in July 2025, as well as the older CVE-2020-1147 ViewState issue and CVE-2019-0604 picker validation flaw. The 2026-05-22 disclosure differs in that exploitation requires authentication (PR:L) — an attacker must hold at least SharePoint Site Member credentials — but the network-reachable attack surface (AV:N), low attack complexity (AC:L), and full confidentiality/integrity/availability impact (C:H/I:H/A:H) make it an attractive secondary-stage objective after credential theft, phishing, password spray, or session-cookie replay.

Exploit chain (expected, based on family precedent): (1) initial access — attacker harvests valid SharePoint user credentials via phishing/password-spray/cookie-replay or pivots from an already-compromised endpoint; (2) authentication to the target SharePoint web front end over HTTPS; (3) delivery of a crafted serialized .NET object — typically embedded in a request to a vulnerable handler such as the picker callback, web part property bag, ViewState, or list event receiver — using publicly available tooling such as ysoserial.net to produce TypeConfuseDelegate or other gadget chains targeting Microsoft.SharePoint.dll; (4) the application pool worker process deserializes the payload, instantiates the malicious object graph, and executes attacker code; (5) post-exploitation typically follows the ToolShell playbook — drop a small ASPX webshell (e.g., spinstall0.aspx) inside the LAYOUTS directory, extract the SharePoint MachineKey ValidationKey/DecryptionKey for persistent payload forging, enumerate site collections, dump content database connection strings, and pivot via Kerberos delegation or saved credentials. Threat actors known to have weaponised the prior SharePoint family include Linen Typhoon, Violet Typhoon, and Storm-2603 (Microsoft naming); historical actors with deep SharePoint deserialization tradecraft include APT41 and the Hafnium-adjacent clusters.

Indicator and detection priorities: w3wp.exe spawning cmd.exe / powershell.exe / csc.exe / cscript.exe; ASPX file writes to the LAYOUTS, _layouts, or TEMPLATE directories under the SharePoint hive; unusual base64 or gzip blobs in POST bodies to /_layouts/15/, /_layouts/16/, /_vti_bin/, or list/library endpoints; outbound TLS from SharePoint farms to non-Microsoft destinations; ASP.NET deserialization exceptions (event ID 1310) immediately preceded or followed by w3wp.exe child process creation; machine-key disclosure events (file reads on web.config from non-administrative processes).

Microsoft shipped patches via the May 2026 Patch Tuesday release. Organizations running SharePoint Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016 should apply the relevant security update KB, rotate the SharePoint MachineKey ValidationKey and DecryptionKey post-patch (the rotation is essential because attackers who reached an unpatched server can forge signed payloads indefinitely without it), restart IIS, and audit for the post-exploitation indicators above. On-premise SharePoint farms exposed directly to the internet should be prioritised; defenders should also restrict SharePoint authentication to corporate identity providers with MFA and revoke service-principal/long-lived tokens.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1078.002 Valid Accounts: Domain Accounts
- T1566 Phishing
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1106 Native API
- T1505.003 Server Software Component: Web Shell
- T1098 Account Manipulation
- T1068 Exploitation for Privilege Escalation
- T1055 Process Injection
- T1036.005 Match Legitimate Resource Name or Location
- T1070.004 Indicator Removal: File Deletion
- T1027 Obfuscated Files or Information
- T1003.001 OS Credential Dumping: LSASS Memory
- T1552.001 Unsecured Credentials: Credentials In Files
- T1606 Forge Web Credentials
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1087.002 Account Discovery: Domain Account
- T1021.002 Remote Services: SMB/Windows Admin Shares
- T1550 Use Alternate Authentication Material
- T1213.002 Data from Information Repositories: SharePoint
- T1071.001 Application Layer Protocol: Web Protocols
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel

## Sources

- [NVD - CVE-2026-45659 Detail](https://nvd.nist.gov/vuln/detail/CVE-2026-45659)
- [MSRC Security Update Guide - CVE-2026-45659](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659)
- [MITRE CWE-502: Deserialization of Untrusted Data](https://cwe.mitre.org/data/definitions/502.html)
- [Microsoft - Disrupting active exploitation of on-premises SharePoint vulnerabilities (ToolShell precedent)](https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/)
- [CISA Alert - Active Exploitation of Microsoft SharePoint Vulnerabilities (ToolShell)](https://www.cisa.gov/news-events/alerts/2025/07/20/active-exploitation-microsoft-sharepoint-vulnerabilities)
- [ysoserial.net - .NET deserialization gadget chain generator](https://github.com/pwntester/ysoserial.net)
- [MITRE ATT&CK T1190 - Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190/)
- [MITRE ATT&CK T1505.003 - Server Software Component: Web Shell](https://attack.mitre.org/techniques/T1505/003/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0589
