Vulnerabilità ed exploit
L'accesso Site Member può compromettere SharePoint Un account SharePoint con solo accesso Site Member può essere sufficiente per raggiungere l'esecuzione di codice su un server esposto. Microsoft ha corretto CVE-2026-45659 , una falla di deserializzazione che consente a un attaccante autenticato di eseguire codice senza diritti di amministratore o interazione dell'utente.
3 fonti · 26 mag
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 8.8 HIGH: deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a… EPSS 3% (85º percentile). Patch Microsoft: 5002868.
Patch disponibile KB5002868 Scarica →
Data di correzione federale CISA 4 lug
Cronologia Fonti 26 mag Dark Reading
Microsoft Issues Out-of-Band SharePoint Patch
SharePoint often gives access to the keys of the kingdom, something attackers and defenders understand all too well.
originale 26 mag The Hacker News
Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions
Microsoft released fixes for SharePoint remote code execution vulnerability CVE-2026-45659 with a CVSS score of 8.8.
originale 26 mag Help Net Security
High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659) - Help Net Security
A high-severity remote code execution vulnerability (CVE-2026-45659) in SharePoint may be exploited in low-complexity attacks.
originale Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-05-27
Every edition of this story: L'accesso Site Member può compromettere SharePoint
Altro da oggi
Vulnerabilità ed exploit
L'accesso Site Member può compromettere SharePoint Un account SharePoint con solo accesso Site Member può essere sufficiente per raggiungere l'esecuzione di codice su un server esposto. Microsoft ha corretto CVE-2026-45659 , una falla di deserializzazione che consente a un attaccante autenticato di eseguire codice senza diritti di amministratore o interazione dell'utente.
3 fonti · 26 mag
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 8.8 HIGH: deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a… EPSS 3% (85º percentile). Patch Microsoft: 5002868.
Patch disponibile KB5002868 Scarica →
Data di correzione federale CISA 4 lug
Cronologia Fonti 26 mag Dark Reading
Microsoft Issues Out-of-Band SharePoint Patch
SharePoint often gives access to the keys of the kingdom, something attackers and defenders understand all too well.
originale 26 mag The Hacker News
Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions
Microsoft released fixes for SharePoint remote code execution vulnerability CVE-2026-45659 with a CVSS score of 8.8.
originale 26 mag Help Net Security
High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659) - Help Net Security
A high-severity remote code execution vulnerability (CVE-2026-45659) in SharePoint may be exploited in low-complexity attacks.
originale Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-05-27
Every edition of this story: L'accesso Site Member può compromettere SharePoint
Altro da oggi