# CVE-2026-45659: Microsoft SharePoint Server Deserialization RCE Actively Exploited, Added to CISA KEV

> CVE-2026-45659 is a CWE-502 deserialization-of-untrusted-data flaw (CVSS 3.1 8.8) in on-premises Microsoft SharePoint Server (Enterprise Server 2016, Server 2019, Subscription Edition) that lets an authenticated Site Member execute arbitrary code remotely via a crafted SPListItem field payload processed by LosFormatter.Deserialize. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-07-01 with a 2026-07-04 federal remediation deadline after confirming in-the-wild exploitation; no confirmed ransomware linkage or actor attribution has been publicly reported.

- **Published:** 2026-07-02T00:00:00Z
- **Last reviewed:** 2026-07-02T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1066
- **ID:** TL-2026-1066
- **Severity:** CRITICAL (CVSS 8.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 18 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-45659

## Description

CVE-2026-45659 affects the SPListItem handling path in Microsoft.SharePoint.Library, specifically the Update() method used when custom list-item field types employ ViewState-like serialization. The vulnerable code invokes LosFormatter.Deserialize on data that is partially attacker-controlled through the field payload, without applying ObjectStateFormatter type restrictions or an allow-list on deserialized types. An attacker who holds only Site Member (Contribute) level credentials -- no elevated or administrative access -- can submit a crafted serialized object graph through a standard list-item Update() call issued via REST or CSOM. Because .NET deserialization of untyped/untrusted binary or LosFormatter payloads can invoke arbitrary constructors, property setters, and IDisposable/finalizer paths on attacker-chosen types already loaded in the SharePoint application domain (a 'gadget chain'), a suitably chosen chain results in arbitrary code execution in the context of the SharePoint application pool identity -- a foothold from which post-exploitation activity (credential harvesting from SharePoint/ADFS-connected accounts, lateral movement across the farm, web-shell persistence, and further internal reconnaissance) is realistically achievable, mirroring the pattern seen in prior on-prem SharePoint RCE chains such as ToolShell/CVE-2025-53770.

Microsoft rated the flaw 'Important' (CVSS 3.1 8.8, AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) and shipped fixes on 2026-05-12 for SharePoint Server Subscription Edition (KB5002863, fixed build 16.0.19725.20280), SharePoint Server 2019 (KB5002870, fixed build 16.0.10417.20128), and SharePoint Enterprise Server 2016 (KB5002868, fixed build 16.0.5552.1002). The advisory credits a researcher using the handle 'MEOW'. Due to an administrative error the CVE entry was omitted from Microsoft's initial May 2026 Patch Tuesday summary and the advisory was republished on 2026-05-26/27 to correct the omission -- organizations that already installed the May 2026 cumulative updates are protected and need no further action, but this publication gap likely delayed patch-prioritization triage at organizations relying on bulletin summaries rather than build-number checks. At disclosure, Microsoft assessed exploitation as 'less likely' and no public PoC was known to exist.

That assessment changed by 2026-07-01, when CISA added CVE-2026-45659 to the KEV catalog after confirming active in-the-wild exploitation, triggering a compressed 3-day BOD 22-01 remediation window (deadline 2026-07-04) for FCEB agencies -- consistent with CISA's treatment of actively-exploited on-prem SharePoint RCEs as urgent, internet-facing crown-jewel risks. Independently, a public Python proof-of-concept (cve-2026-45659.py) has since surfaced on GitHub that automates the attack chain: it authenticates as a low-privilege user, issues the crafted list-item update, and supports single-command execution (-c flag), an interactive netcat-based reverse shell mode, HTTP proxy support for routing through intercepting proxies/C2 redirectors, and a quiet/non-verbose output mode -- material that materially lowers the skill bar for exploitation and should be treated as a strong signal that opportunistic scanning and exploitation will accelerate. On-premises SharePoint Server is a historically high-value target for both financially motivated and state-nexus intrusion sets (e.g. the July 2025 ToolShell campaign attributed to China-nexus actors), and any internet-facing, unpatched SharePoint farm should be treated as compromised-until-proven-otherwise once a working PoC is public and KEV-listed.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1203 Exploitation for Client Execution
- T1059 Command and Scripting Interpreter
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1505.003 Web Shell
- T1543 Create or Modify System Process
- T1068 Exploitation for Privilege Escalation
- T1140 Deobfuscate/Decode Files or Information
- T1070 Indicator Removal
- T1003 OS Credential Dumping
- T1552 Unsecured Credentials
- T1016 System Network Configuration Discovery
- T1087 Account Discovery
- T1021 Remote Services
- T1213 Data from Information Repositories
- T1071 Application Layer Protocol
- T1090 Proxy
- T1041 Exfiltration Over C2 Channel
- T1486 Data Encrypted for Impact
- T1587.004 Exploits

## Sources

- [SharePoint Server Code Execution Vulnerability Actively Exploited](https://cybersecuritynews.com/sharepoint-server-code-execution-vulnerability-exploited/)
- [Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions](https://thehackernews.com/2026/05/microsoft-patches-sharepoint-rce-flaw.html)
- [High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659)](https://www.helpnetsecurity.com/2026/05/26/sharepoint-vulnerability-cve-2026-45659/)
- [CVE-2026-45659-SharePoint-RCE proof-of-concept](https://github.com/mistbarbarianspot/CVE-2026-45659-SharePoint-RCE)
- [Microsoft Security Response Center - CVE-2026-45659 Vulnerability Update Guide](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659)
- [CISA Known Exploited Vulnerabilities Catalog - CVE-2026-45659](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-45659)
- [NVD - CVE-2026-45659 Detail](https://nvd.nist.gov/vuln/detail/CVE-2026-45659)
- [CVE-2026-45659 Microsoft SharePoint RCE Flaw Patched Across Server Versions](https://vulert.com/blog/cve-2026-45659-microsoft-sharepoint-rce-flaw/)
- [Remote Code Execution in Microsoft SharePoint via Deserialization of Untrusted Data (CVE-2026-45659)](https://www.mallory.ai/vulnerabilities/019e5017-f890-76ee-8d04-cdd7378ce7a9)
- [CVE-2026-45659: CWE-502 Deserialization of Untrusted Data - Threat Radar](https://radar.offseq.com/threat/cve-2026-45659-cwe-502-deserialization-of-untruste-e564b24e)
- [SharePoint Security Advisory: Understanding CVE-2026-45659 and CVE-2026-47294](https://www.5tattva.com/post/sharepoint-security-advisory-understanding-cve-2026-45659-and-cve-2026-47294)
- [CVE-2026-45659: Microsoft fixes a major SharePoint RCE flaw](https://sharkstriker.com/blog/cve-2026-45659-microsoft-patches-a-major-rce-vulnerability-in-sharepoint/)
- [SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation](https://thehackernews.com/2026/07/sharepoint-rce-cve-2026-45659-added-to.html)
- [Microsoft SharePoint Has a New RCE Flaw. If You Haven't Patched Yet, Go Do That.](https://securityaffairs.com/192730/security/microsoft-sharepoint-has-a-new-rce-flaw-if-you-havent-patched-yet-go-do-that.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1066
