A SharePoint account with only Site Member access can be enough to reach code execution on an exposed server. Microsoft fixed CVE-2026-45659, a deserialization flaw that lets an authenticated attacker run code without admin rights or user interaction. The patch applies to SharePoint Server Subscription Edition 16.0.19725.20280, SharePoint Server 2019 16.0.10417.20128, and SharePoint Enterprise Server 2016 16.0.5552.1002. On-prem deployments that let ordinary users post content or otherwise authenticate to the server are the ones in scope.
Part of the PlainSec briefing for 2026-05-27