CVE-2026-45659: Microsoft SharePoint Deserialization RCE Actively Exploited, Added to CISA KEV — Threadlinqs Intelligence
As of 2026-07-02, CVE-2026-45659: Microsoft SharePoint Deserialization RCE Actively Exploited, Added to CISA KEV is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-1068 · Severity: HIGH · CVSS: 8.8 · Status: ACTIVE · Category: VULNERABILITY
CVE-2026-45659 is a CVSS 8.8 deserialization-of-untrusted-data remote code execution vulnerability in Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server
CVE-2026-45659 is a deserialization-of-untrusted-data vulnerability (CWE-502) in Microsoft Office SharePoint that allows an authenticated attacker holding only minimum Site Member permissions to execute arbitrary code remotely over the network, with no user interaction required. The flaw carries a CVSS 3.1 base score of 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H): network attack vector, low attack complexity, low privileges required, no user interaction, and high impact to confidentiality, integrity, and availability. Microsoft patched the vulnerability on 2026-05-21 (initially omitted from the scheduled May 2026 Patch Tuesday release and shipped as an out-of-band/emergency addition) for SharePoint Server Subscription Edition (build 16.0.19725.20280, KB5002863), SharePoint Server 2019 (build 16.0.10417.20128, KB5002870), and SharePoint Enterprise Server 2016 (build 16.0.5552.1002, KB5002868). At disclosure, Microsoft assessed the flaw as 'Exploitation Less Likely' and no public exploitation was known. That assessment proved incorrect: CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities (KEV) catalog on 2026-07-01 after observing evidence of active exploitation in the wild, invoking Binding Operational Directive 26-04 and ordering Federal Civilian Executive Branch (FCEB) agencies to remediate by 2026-07-04/05 (a 3-day window reflecting active-exploitation urgency). As of KEV addition, the specific exploitation vector in the wild, the identity of the threat actor(s), and campaign objectives (espionage vs. financially motivated ransomware/extortion) were not publicly confirmed by CISA or Microsoft. Shadowserver Foundation honeypot/internet-scan telemetry identified more than 10,000 internet-facing SharePoint servers still reachable online with unknown patch status, representing a large exposed attack surface. The vulnerability chain fits a well-established pattern for on-premises SharePoint: an authenticated, low-privileged user submits a specially crafted serialized object to a vulnerable SharePoint endpoint/web service; SharePoint's server-side deserialization logic instantiates the object without adequate type/origin validation, triggering a gadget chain that results in arbitrary .NET code execution in the context of the SharePoint application pool (typically NT AUTHORITY\SYSTEM or a highly privileged service account on IIS). Successful exploitation grants a foothold suitable for webshell deployment, credential/token theft (including machine keys used to forge ViewState payloads, a technique repeatedly abused in prior SharePoint RCE chains), lateral movement across the SharePoint farm and connected Active Directory environment, and downstream ransomware or espionage objectives. This disclosure lands roughly one year after Microsoft on-premises SharePoint suffered the widely exploited 'ToolShell' vulnerability chain (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771) which the China-nexus, dual-purpose (espionage + ransomware) actor Storm-2603 weaponized at scale in July 2025 to deploy Warlock and LockBit Black ransomware and a custom DNS-tunneling backdoor across government and critical-infrastructure targets, including a US nuclear weapons agency facility. CVE-2026-45659 was also patched roughly one month after another actively exploited SharePoint flaw, the spoofing/reflected-XSS vulnerability CVE-2026-32201 (CVSS 6.5, CWE-20 improper input validation), which was itself observed under active exploitation against 1,300+ internet-exposed SharePoint servers to steal session cookies and NTLM tokens via crafted page parameters, ahead of its April 2026 patch. This repeated pattern of chained, actively-exploited on-premises SharePoint vulnerabilities makes CVE-2026-45659 a high-priority patch/hunt target: on-prem SharePoint has become a recurring beachhead for nation-state-linked ransomware crews targeting government, critical infrastructure, and enterprise environments worldwide, and organizations running e
Weaknesses (CWE)
CWE-502, CWE-20
Target sectors: government administration, critical infrastructure, enterprise, technology, health, finance
Target regions: Global, North America
Detections & IOCs
As of 2026-08-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2026-45659, CVE-2026-32201, T1190, T1078, T1203, T1059, T1059.001, T1505.003, T1543, T1068, T1218, T1685