Vulnerabilities · 111 days ago

Site Member Access Can Break SharePoint

A SharePoint account with only Site Member access can be enough to reach code execution on an exposed server. Microsoft fixed CVE-2026-45659, a deserialization flaw that lets an authenticated attacker run code without admin rights or user interaction.

The patch applies to SharePoint Server Subscription Edition 16.0.19725.20280, SharePoint Server 2019 16.0.10417.20128, and SharePoint Enterprise Server 2016 16.0.5552.1002. On-prem deployments that let ordinary users post content or otherwise authenticate to the server are the ones in scope.

CVE-2026-45659

NVD KEV

Known exploited · CISA KEV

CVSS 8.8 HIGH: deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a… EPSS 76% (99th percentile). Microsoft patch: 5002868.

Patch available KB5002868 Download →

CISA federal remediation date Jul 4

Timeline

Sources

3 sources covering this story

Entities

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-05-27

Editions

Related stories