Vulnerabilities & Exploits
Site Member Access Can Break SharePoint A SharePoint account with only Site Member access can be enough to reach code execution on an exposed server. Microsoft fixed CVE-2026-45659 , a deserialization flaw that lets an authenticated attacker run code without admin rights or user interaction.
The patch applies to SharePoint Server Subscription Edition 16.0.19725.20280 , SharePoint Server 2019 16.0.10417.20128 , and SharePoint Enterprise Server 2016 16.0.5552.1002 . On-prem deployments that let ordinary users post content or otherwise authenticate to the server are the ones in scope.
3 sources · May 26
NVD KEV
Known exploited · CISA KEV
CVSS 8.8 HIGH: deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a… EPSS 76% (99th percentile). Microsoft patch: 5002868.
Patch available KB5002868 Download →
CISA federal remediation date Jul 4
Timeline Sources May 26 Dark Reading
Microsoft Issues Out-of-Band SharePoint Patch
SharePoint often gives access to the keys of the kingdom, something attackers and defenders understand all too well.
original May 26 The Hacker News
Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions
Microsoft released fixes for SharePoint remote code execution vulnerability CVE-2026-45659 with a CVSS score of 8.8.
original May 26 Help Net Security
High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659) - Help Net Security
A high-severity remote code execution vulnerability (CVE-2026-45659) in SharePoint may be exploited in low-complexity attacks.
original Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-05-27
Every edition of this story: Site Member Access Can Break SharePoint
More from today
Vulnerabilities & Exploits
Site Member Access Can Break SharePoint A SharePoint account with only Site Member access can be enough to reach code execution on an exposed server. Microsoft fixed CVE-2026-45659 , a deserialization flaw that lets an authenticated attacker run code without admin rights or user interaction.
The patch applies to SharePoint Server Subscription Edition 16.0.19725.20280 , SharePoint Server 2019 16.0.10417.20128 , and SharePoint Enterprise Server 2016 16.0.5552.1002 . On-prem deployments that let ordinary users post content or otherwise authenticate to the server are the ones in scope.
3 sources · May 26
NVD KEV
Known exploited · CISA KEV
CVSS 8.8 HIGH: deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a… EPSS 76% (99th percentile). Microsoft patch: 5002868.
Patch available KB5002868 Download →
CISA federal remediation date Jul 4
Timeline Sources May 26 Dark Reading
Microsoft Issues Out-of-Band SharePoint Patch
SharePoint often gives access to the keys of the kingdom, something attackers and defenders understand all too well.
original May 26 The Hacker News
Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions
Microsoft released fixes for SharePoint remote code execution vulnerability CVE-2026-45659 with a CVSS score of 8.8.
original May 26 Help Net Security
High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659) - Help Net Security
A high-severity remote code execution vulnerability (CVE-2026-45659) in SharePoint may be exploited in low-complexity attacks.
original Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-05-27
Every edition of this story: Site Member Access Can Break SharePoint
More from today