# CVE-2026-45659: SharePoint Deserialization RCE Added to CISA KEV Amid Storm-2603 Exploitation

> CVE-2026-45659 is a deserialization-of-untrusted-data remote code execution flaw in on-premises Microsoft SharePoint Server (Subscription Edition, 2019, and Enterprise Server 2016) that lets an authenticated Site Member trigger unsafe LosFormatter deserialization via the list-item Update() method. CISA added it to the KEV catalog on 2026-07-01 following confirmed active exploitation, with the activity associated with Storm-2603, a China-nexus actor that has exploited prior SharePoint flaws (the 2025 'ToolShell' chain) since mid-2025 to deploy Warlock/AK47 ransomware and the AK47C2 backdoor; the specific 2026-45659 exploitation method and campaign objectives remain unconfirmed as of this writing.

- **Published:** 2026-07-02T00:00:00Z
- **Last reviewed:** 2026-07-02T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1061
- **ID:** TL-2026-1061
- **Severity:** HIGH (CVSS 8.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Actor:** Storm-2603 (China)
- **Detections:** 9 · **IOCs:** 30 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-45659, CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771

## Description

CVE-2026-45659 is a remote code execution vulnerability affecting on-premises Microsoft SharePoint Server (Subscription Edition, Server 2019, and Enterprise Server 2016 — SharePoint Online/Microsoft 365 are not affected). The root cause is unsafe deserialization of untrusted data: the vulnerable code path in Microsoft.SharePoint.Library invokes LosFormatter.Deserialize on attacker-controlled data passed through the Update() method of SPListItem objects when custom field types using ViewState-like serialization are processed, with no proper type filtering or ObjectStateFormatter restrictions in place. An authenticated attacker holding only Site Member-level permissions (PR:L) and Contribute rights to a list containing at least one editable item can submit a crafted serialized payload and achieve arbitrary code execution on the server over HTTPS, with no user interaction required and low attack complexity (CVSS 3.1: 8.8, AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Microsoft fixed the flaw in the May 2026 security updates (Subscription Edition build 16.0.19725.20280, Server 2019 build 16.0.10417.20128, Enterprise Server 2016 build 16.0.5552.1002), but the vulnerability was inadvertently omitted from the original security advisories and only formally disclosed alongside a parallel Microsoft Incident Response blog on 2026-06-22 describing related threat activity. CISA added CVE-2026-45659 to the Known Exploited Vulnerabilities (KEV) catalog on 2026-07-01 based on confirmed evidence of active exploitation in the wild, despite Microsoft's own severity tag of 'Exploitation Less Likely.' Federal Civilian Executive Branch (FCEB) agencies face a remediation deadline of 2026-07-04 under BOD 22-01/26-04. A public proof-of-concept exploit (Python, using the -t/-u/-p/-s/-c argument pattern against a target SharePoint list) is available on GitHub, demonstrating both single-command execution and interactive reverse-shell modes.

The activity is attributed to Storm-2603 (Palo Alto designation CL-CRI-1040), a China-nexus threat actor first identified during the July 2025 'ToolShell' SharePoint campaign (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771), which chained a spoofing bug and an RCE to drop the spinstall0.aspx web shell and exfiltrate SharePoint MachineKey material for forged ViewState/deserialization exploitation even after patching. That 2025 campaign affected at least 400 known victims globally and evolved into ransomware operations: Storm-2603 modified Group Policy Objects to mass-deploy Warlock ransomware, used BYOVD techniques and services.exe abuse to disable Defender, dumped LSASS credentials with Mimikatz, moved laterally with PsExec and Impacket, and used masscan/SharpHostInfo for internal reconnaissance. Storm-2603's custom 'Project AK47' toolkit includes the AK47C2 backdoor (DNS-based 'dnsclient' and HTTP-based 'httpclient' variants, both using a shared XOR key and JSON command protocol) and AK47/X2ANYLOCK ransomware (AES+RSA encryption, .x2anylock extension, Tox-based extortion negotiation). Infrastructure and Tox-ID overlap ties the 'wlteaml' LockBit 3.0 affiliate identity, the Warlock Client Leaked Data Show dark-web leak site, and prior LockBit Black double-extortion operations to the same actor cluster, indicating a hybrid espionage/financially-motivated operation blurring APT and ransomware-affiliate lines. As of the KEV addition, the specific exploitation vector and campaign goals for CVE-2026-45659 itself have not been publicly detailed, but the actor's established playbook (web shell/deserialization foothold → credential theft → lateral movement → GPO-based ransomware deployment) is the primary expected escalation path for unpatched, internet-facing SharePoint servers.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1059 Command and Scripting Interpreter
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1047 Windows Management Instrumentation
- T1203 Exploitation for Client Execution
- T1505 Server Software Component
- T1505.003 Web Shell
- T1505.004 IIS Components
- T1053.005 Scheduled Task
- T1484.001 Group Policy Modification
- T1685 Disable or Modify Tools
- T1112 Modify Registry
- T1574.001 DLL
- T1027 Obfuscated Files or Information
- T1003.001 LSASS Memory
- T1120 Peripheral Device Discovery
- T1135 Network Share Discovery
- T1016 System Network Configuration Discovery
- T1021 Remote Services
- T1570 Lateral Tool Transfer
- T1119 Automated Collection
- T1071.001 Web Protocols
- T1071.004 DNS
- T1090.002 External Proxy
- T1041 Exfiltration Over C2 Channel
- T1486 Data Encrypted for Impact

## Sources

- [SharePoint RCE (CVE-2026-45659) Added to CISA KEV Catalog](https://thehackernews.com/2026/07/sharepoint-rce-cve-2026-45659-added-to.html)
- [Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions](https://thehackernews.com/2026/05/microsoft-patches-sharepoint-rce-flaw.html)
- [High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659)](https://www.helpnetsecurity.com/2026/05/26/sharepoint-vulnerability-cve-2026-45659/)
- [CVE-2026-45659-SharePoint-RCE proof-of-concept](https://github.com/mistbarbarianspot/CVE-2026-45659-SharePoint-RCE)
- [Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [Storm-2603 Deploys DNS-Controlled Backdoor in Warlock and LockBit Ransomware Attacks](https://thehackernews.com/2025/08/storm-2603-exploits-sharepoint-flaws-to.html)
- [Storm-2603 Exploits SharePoint Flaws to Deploy Warlock Ransomware on Unpatched Systems](https://thehackernews.com/2025/07/storm-2603-exploits-sharepoint-flaws-to.html)
- [Project AK47: Uncovering a Link to the SharePoint Vulnerability Attacks](https://unit42.paloaltonetworks.com/ak47-activity-linked-to-sharepoint-vulnerabilities/)
- [Disrupting active exploitation of on-premises SharePoint vulnerabilities](https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/)
- [Before ToolShell: Exploring Storm-2603's Previous Ransomware Operations](https://research.checkpoint.com/2025/before-toolshell-exploring-storm-2603s-previous-ransomware-operations/)
- [ToolShell under siege: Check Point analyzes Chinese APT Storm-2603](https://securityaffairs.com/180657/apt/toolshell-under-siege-check-point-analyzes-chinese-apt-storm-2603.html)
- [Storm-2603: Targeting SharePoint Vulnerabilities and Critical Infrastructure Worldwide](https://www.levelblue.com/blogs/levelblue-blog/storm-2603-targeting-sharepoint-vulnerabilities-and-critical-infrastructure-worldwide)
- [Microsoft SharePoint Has a New RCE Flaw. If You Haven't Patched Yet, Go Do That.](https://securityaffairs.com/192730/security/microsoft-sharepoint-has-a-new-rce-flaw-if-you-havent-patched-yet-go-do-that.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1061
