Threat reportVulnerabilityTL-2026-1066

CVE-2026-45659: Microsoft SharePoint Server Deserialization RCE Actively Exploited, Added to CISA KEV

criticalACTIVE

CVE-2026-45659 (TL-2026-1066) is a critical-severity software vulnerability scored CVSS 8.8, first published 2026-07-02. It has no confirmed attribution, affects Microsoft SharePoint Enterprise Server 2016, references 1 CVE (CVE-2026-45659), maps to 22 MITRE ATT&CK techniques (T1003, T1016, T1021), and is covered by 9 detection rules and 18 indicators of compromise.

CVSS
8.8/10Critical
CVEs
1Referenced vulnerabilities
Techniques
22MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
18Indicators of compromise

Key facts for TL-2026-1066

Threat ID
TL-2026-1066
Severity
CRITICAL
CVSS
8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, health, education, technology, professionalservices
Target regions
North America, Europe, Asia Pacific, Global
Detection rules
9
Indicators of compromise
18

Malware and tooling in CVE-2026-45659

Malware and tooling: WarLock, Netcat, cve-2026-45659.py

How CVE-2026-45659 works

CVE-2026-45659 is a CWE-502 deserialization-of-untrusted-data flaw (CVSS 3.1 8.8) in on-premises Microsoft SharePoint Server (Enterprise Server 2016, Server 2019, Subscription Edition) that lets an authenticated Site Member execute arbitrary code remotely via a crafted SPListItem field payload processed by LosFormatter.Deserialize. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-07-01 with a 2026-07-04 federal remediation deadline after confirming in-the-wild exploitation; no confirmed ransomware linkage or actor attribution has been publicly reported.

CVE-2026-45659 affects the SPListItem handling path in Microsoft.SharePoint.Library, specifically the Update() method used when custom list-item field types employ ViewState-like serialization. The vulnerable code invokes LosFormatter.Deserialize on data that is partially attacker-controlled through the field payload, without applying ObjectStateFormatter type restrictions or an allow-list on deserialized types. An attacker who holds only Site Member (Contribute) level credentials -- no elevated or administrative access -- can submit a crafted serialized object graph through a standard list-item Update() call issued via REST or CSOM. Because .NET deserialization of untyped/untrusted binary or LosFormatter payloads can invoke arbitrary constructors, property setters, and IDisposable/finalizer paths on attacker-chosen types already loaded in the SharePoint application domain (a 'gadget chain'), a suitably chosen chain results in arbitrary code execution in the context of the SharePoint application pool identity -- a foothold from which post-exploitation activity (credential harvesting from SharePoint/ADFS-connected accounts, lateral movement across the farm, web-shell persistence, and further internal reconnaissance) is realistically achievable, mirroring the pattern seen in prior on-prem SharePoint RCE chains such as ToolShell/CVE-2025-53770.

Microsoft rated the flaw 'Important' (CVSS 3.1 8.8, AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) and shipped fixes on 2026-05-12 for SharePoint Server Subscription Edition (KB5002863, fixed build 16.0.19725.20280), SharePoint Server 2019 (KB5002870, fixed build 16.0.10417.20128), and SharePoint Enterprise Server 2016 (KB5002868, fixed build 16.0.5552.1002). The advisory credits a researcher using the handle 'MEOW'. Due to an administrative error the CVE entry was omitted from Microsoft's initial May 2026 Patch Tuesday summary and the advisory was republished on 2026-05-26/27 to correct the omission -- organizations that already installed the May 2026 cumulative updates are protected and need no further action, but this publication gap likely delayed patch-prioritization triage at organizations relying on bulletin summaries rather than build-number checks. At disclosure, Microsoft assessed exploitation as 'less likely' and no public PoC was known to exist.

That assessment changed by 2026-07-01, when CISA added CVE-2026-45659 to the KEV catalog after confirming active in-the-wild exploitation, triggering a compressed 3-day BOD 22-01 remediation window (deadline 2026-07-04) for FCEB agencies -- consistent with CISA's treatment of actively-exploited on-prem SharePoint RCEs as urgent, internet-facing crown-jewel risks. Independently, a public Python proof-of-concept (cve-2026-45659.py) has since surfaced on GitHub that automates the attack chain: it authenticates as a low-privilege user, issues the crafted list-item update, and supports single-command execution (-c flag), an interactive netcat-based reverse shell mode, HTTP proxy support for routing through intercepting proxies/C2 redirectors, and a quiet/non-verbose output mode -- material that materially lowers the skill bar for exploitation and should be treated as a strong signal that opportunistic scanning and exploitation will accelerate. On-premises SharePoint Server is a historically high-value target for both financially motivated and state-nexus intrusion sets (e.g. the July 2025 ToolShell campaign attributed to China-nexus actors), and any internet-facing, unpatched SharePoint farm should be treated as compromised-until-proven-otherwise once a working PoC is public and KEV-listed.

MITRE ATT&CK techniques used in TL-2026-1066

Credential Access

T1003 OS Credential Dumping; T1552 Unsecured Credentials

Discovery

T1016 System Network Configuration Discovery; T1087 Account Discovery

Lateral Movement

T1021 Remote Services

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059 Command and Scripting Interpreter; T1059.001 PowerShell; T1059.003 Windows Command Shell; T1203 Exploitation for Client Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Defense Evasion

T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information

Command and Control

T1071 Application Layer Protocol; T1090 Proxy

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Collection

T1213 Data from Information Repositories

Impact

T1486 Data Encrypted for Impact

Persistence

T1505.003 Web Shell; T1543 Create or Modify System Process

Resource Development

T1587.004 Exploits

Affected products and versions in CVE-2026-45659

  • Microsoft — SharePoint Enterprise Server 2016
    Vulnerable versions: before 16.0.5552.1002
    Fixed in: 16.0.5552.1002 (KB5002868)
  • Microsoft — SharePoint Server 2019
    Vulnerable versions: before 16.0.10417.20128
    Fixed in: 16.0.10417.20128 (KB5002870)
  • Microsoft — SharePoint Server Subscription Edition
    Vulnerable versions: before 16.0.19725.20280
    Fixed in: 16.0.19725.20280 (KB5002863)

Remediation for CVE-2026-45659

Patches

  • KB5002863 - SharePoint Server Subscription Edition, released 2026-05-12, fixed build 16.0.19725.20280
  • KB5002870 - SharePoint Server 2019, released 2026-05-12, fixed build 16.0.10417.20128
  • KB5002868 - SharePoint Enterprise Server 2016, released 2026-05-12, fixed build 16.0.5552.1002

Immediate actions

  • Apply KB5002863 (SharePoint Server Subscription Edition), KB5002870 (SharePoint Server 2019), or KB5002868 (SharePoint Enterprise Server 2016) immediately
  • Verify patched build numbers directly (16.0.19725.20280 / 16.0.10417.20128 / 16.0.5552.1002) rather than trusting Patch Tuesday summaries, since this CVE was omitted from the initial May 2026 bulletin
  • Comply with CISA BOD 22-01 / BOD 26-04 remediation deadline of 2026-07-04 for federal systems
  • Assess internet exposure of on-premises SharePoint servers and restrict access where patching cannot be completed immediately
  • Perform forensic triage of SharePoint logs (IIS logs, ULS logs, w3wp.exe process activity) for anomalous list-item Update() calls and unexpected child processes spawned by the SharePoint application pool
  • Rotate SharePoint machine keys / ASP.NET machine keys and application-pool service account credentials on any server suspected of exploitation, consistent with guidance issued for prior SharePoint deserialization chains

Workarounds

  • Restrict list-item edit (Contribute/Site Member) permissions to trusted users only where patching is delayed
  • Block or closely monitor direct internet exposure of on-premises SharePoint farms pending patch deployment
  • Enable AMSI integration for SharePoint Server where supported to aid detection of malicious deserialization payloads

Longer-term hardening

  • Deploy EDR with behavioral detection on all SharePoint farm servers, specifically alerting on w3wp.exe / SharePoint app-pool processes spawning cmd.exe, powershell.exe, or unexpected child processes
  • Segment on-premises SharePoint servers from the internet where business need does not require direct exposure; place behind a reverse proxy / WAF with virtual patching
  • Implement least-privilege review of Site Member / Contribute-level accounts, since this vulnerability requires only low-privilege authenticated access
  • Establish a build-number verification process for SharePoint patch compliance independent of vendor bulletin summaries

CVEs associated with CVE-2026-45659

CVE-2026-45659

Weaknesses (CWE) in CVE-2026-45659

CWE-502

Timeline of CVE-2026-45659

  • Microsoft releases fixed builds for SharePoint Server Subscription Edition (KB5002863), SharePoint Server 2019 (KB5002870), and SharePoint Enterprise Server 2016 (KB5002868), though the CVE is inadvertently omitted from the public May 2026 Patch Tuesday summary. At disclosure Microsoft rates exploitation 'Less Likely' and no public PoC exists.
  • CVE-2026-45659 is published to the National Vulnerability Database with CVSS 3.1 score 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) and CWE-502 classification.
  • Microsoft republishes/corrects its advisory after discovering CVE-2026-45659 was omitted from the initial May 2026 Security Updates announcement; media coverage of the SharePoint deserialization RCE begins (TheHackerNews, HelpNetSecurity).
  • Additional vendor/blog analyses (5tattva, SharkStriker, Vulert, Mallory.ai, OffSeq Threat Radar) publish technical breakdowns of the LosFormatter deserialization root cause and compare it to the related CVE-2026-47294 SharePoint disclosure.
  • A public Python proof-of-concept (cve-2026-45659.py) targeting the SPListItem deserialization flaw appears on GitHub (mistbarbarianspot/CVE-2026-45659-SharePoint-RCE), supporting single-command execution (-c), an interactive netcat reverse shell (--shell), HTTP proxy routing (--proxy), and quiet output (--quiet) against SharePoint Server 2019, 2022, and Subscription Edition targets.
  • First public threat-intel reporting (Cyber Security News, TheHackerNews) on active exploitation of CVE-2026-45659 in the wild, coinciding with the CISA KEV addition; coverage notes historical parallel to Storm-2603, a threat group that has exploited on-prem SharePoint vulnerabilities to deploy Warlock ransomware since mid-2025, though no confirmed attribution or ransomware linkage exists for this specific campaign.
  • CISA adds CVE-2026-45659 to the Known Exploited Vulnerabilities catalog citing 'evidence of active exploitation,' though CISA and Microsoft state it is not yet known how the vulnerability is being exploited, who is behind the activity, or the end goals of the activity; Microsoft's advisory-listed exploitation assessment still reads 'Exploitation Less Likely' at time of KEV addition.
  • CISA BOD 22-01 / BOD 26-04 remediation deadline for FCEB agencies to patch, mitigate, or discontinue use of vulnerable internet-facing SharePoint servers per CVE-2026-45659's KEV entry.

Sources cited for CVE-2026-45659

Detection coverage for TL-2026-1066

As of 2026-07-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1066 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
18 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats