FR
live
Critical Actively exploited

CVE-2026-45659

Microsoft SharePoint Server

Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

What this means

Weakness
The application rebuilds an object from attacker-controlled data, which often leads to code execution.
Likelihood
Exploitation is not hypothetical: CISA has observed it in the wild.

What to doTop priority: CISA sets the remediation deadline at 4 July 2026.

Read automatically from the CVSS vector, the weakness type (CWE) and the EPSS score. The technical description above remains the one published by NIST.

Published
1 July 2026
CVSS
EPSS
6.92% probability of exploitation within 30 days · above 93% of all CVEs
Weakness
CWE-502
CISA due date
4 July 2026 past due
Sources
cisa-kev
References

Type at least two characters.

navigate open esc dismiss