Sunday, July 26, 2026 · Beirut, Lebanon Newsletter · About · Contact
Cybersecurity

SharePoint flaw CVE-2026-45659 lands on CISA’s must-patch list

Microsoft SharePoint Server has an actively exploited remote-code-execution flaw now on CISA’s must-patch list, with a July 4 federal patch deadline.

I
IT Magazine Staff July 10, 2026 · 1 min read
Cybersecurity

A remote-code-execution vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-45659, has been added to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (KEV) catalog after confirmed exploitation in the wild. Federal civilian agencies were ordered to patch by July 4.

Inclusion in the KEV catalog is CISA’s signal that a flaw is not theoretical but actively being used by attackers. SharePoint is widely deployed for internal document management and collaboration, making a server-side code-execution bug especially serious for organizations that host it on-premises.

According to reporting by The Hacker News, Microsoft had inadvertently omitted CVE-2026-45659 from its initial May 2026 Patch Tuesday release notes and only updated the advisory on May 27 — a gap that can leave defenders unaware a fix exists.

Administrators running SharePoint Server should apply Microsoft’s update immediately and review servers for signs of compromise, following CISA’s guidance regardless of whether they fall under the federal deadline.

Sources: CISA Known Exploited Vulnerabilities Catalog; reported by The Hacker News.

Drafted with AI assistance and reviewed by the IT Magazine news desk. Facts verified against the linked sources. Spotted an error? See our Corrections Policy.

Related stories