KEV alert: CVE-2026-45659 from SharePoint threatens on-premises servers and demands immediate parking

Author: Published 4 min de lectura 186 reading

The images in this article were generated with artificial intelligence. How we publish

The US Agency for Infrastructure and Cybersecurity. US (CISA) has recently included in its catalogue of known and exploited vulnerabilities (KEV) a high-gravity failure affecting Microsoft SharePoint servers: this is the failure recorded as CVE-2026-45659, a remote code execution vulnerability resulting from the deerialization of unreliable data. Although Microsoft corrected it in May 2026 for SharePoint Server Subscription Edition, SharePoint Server 2019 and SharePoint Enterprise Server 2016, the emergence of active operation indicators has forced security teams to accelerate their response, and the deadline recommended by CISA for federal government entities is to apply the patches before 4 July 2026. More general information on the KEV list is available on the CISA website: https: / / www.cisa.gov / knowledge-exploited-vulnerabilities-catalog.

From a technical point of view, vulnerability allows an authenticated attacker with minimum site member privileges to run code on the SharePoint server without administrative credentials. This makes SharePoint on-premises servers particularly attractive because many organizations retain local bodies that integrate automated critical content and workflows and that, by default, expose authentication mechanisms that can be coopted by phishing, filtered credentials or chained exploitation of other failures.

KEV alert: CVE-2026-45659 from SharePoint threatens on-premises servers and demands immediate parking
Image generated with IA.

The Microsoft evaluation described the probability of exploitation as "less likely," but the inclusion in the CISA catalogue by evidence of real abuse shows a common tension between internal risk assessments and field observations. This discrepancy is relevant to security officials: if there is any indication of exploitation, caution requires prioritizing immediate mitigation, regardless of probability labels.

This case comes in a broader context of complex attacks where, according to Microsoft research, actors like Storm-2603 have exploited on-premises servers - including vectors against SharePoint - to deploy ansomware and maintain prolonged access. The attackers combine legitimate management and telemetry tools (e.g. Velociraptor), tunnels through cloud services, and remote access channels such as Zoho Assist or SSH managed by IDEs, as well as privilege climbing techniques and driver handling to evade defenses. Microsoft documents this type of activity on its security blog: https: / / www.microsoft.com / security / blog /.

The operational lesson is clear: an apparently unique incident (a ransomware attack) can hide multiple actors and intrusion chains, which complicates containment and mediation if only the symptom is addressed. Response teams should assume the possibility of parallel activity, seek traces of lateral movements and persistent access, and not limit the investigation to the initial sample of the incident.

In practical and urgent terms, the recommendation for administrators is to prioritize the application of patches published by Microsoft in all environments that run the affected editions of SharePoint. If it is not possible for operational limitations to apply the update immediately, it is appropriate to block or restrict access to SharePoint management interfaces and services from public networks, to strengthen multi-factor authentication controls, to review and minimize site member permissions, and to segment the network so that critical servers do not have direct access routes from workstations or Internet exits.

KEV alert: CVE-2026-45659 from SharePoint threatens on-premises servers and demands immediate parking
Image generated with IA.

For detection and response, signs of abuse associated with the above tactics should be sought: creation of unusual local or domain accounts, installation of remote management tools or tunnels, records showing atypical requests to configuration files (e.g. web.config or win.ini) and typical DLL side-rolling patterns or running unexpected binaries. Correlate EDR events, proxy / reverse proxy and identity telemetry helps to distinguish legitimate activity from malicious; technical details on vulnerability can be found in the NVD base: https: / / nvd.nist.gov / vuln / detail / CVE-2026-45659.

In the medium and long term, it is appropriate to rethink the exposure of critical business services in on-premises: maintain frequent patch cycles, strengthen account control with privileges, monitor encrypted outgoing connections that can be tunnels and validate the integrity of third-party drivers and software. In addition, establishing response processes that consider scenarios with multiple simultaneous adversaries reduces the likelihood of underestimating the scope of an intrusion and facilitates complete containment.

If your organization detects suspicious activity or signs compatible with the exploitation of this vulnerability, it is wise to activate your incident response plan, take immediate containment measures and, if appropriate, seek support from a specialized forensic response team. The official references of CISA and Microsoft, in addition to public vulnerability pages, are useful starting points for testing and prioritizing: review the guidelines in CISA KEV and Microsoft information on Microsoft Security.

Coverage

Related

More news on the same subject.