Skip to main content

Share story

Security

SharePoint CVE-2026-45659 Actively Exploited July 2026

SharePoint CVE-2026-45659 Actively Exploited July 2026 Image: Primary
CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalogue on 1 July 2026. The catalogue lists vulnerabilities confirmed to be actively exploited in the wild. The vulnerability affects Microsoft SharePoint. It permits an attacker with at least basic site member permissions to execute arbitrary code on the SharePoint server by means of deserialisation of untrusted data. Microsoft released a patch for the flaw in May. The company did not publish the security bulletin until 21 May. In the period before the bulletin, organisations had no specific indication that the patch addressed this particular vulnerability. Microsoft had assessed prior to publication that exploitation was less likely. The CISA listing establishes that exploitation is occurring despite that assessment. The issue concerns on-premises SharePoint deployments and servers managed by managed service providers, which require manual patching. SharePoint Online instances hosted in Microsoft 365 receive updates from the provider. The information originates from an article published on 3 July 2026 by Corrine Jefferson on thesmallbusinesscybersecurityguy.co.uk.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Small Business Cybersecurity Guy and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Science
AI Science

AI agents develop physical model from quantum-material observations

Researchers report in an arXiv preprint that their AI Theorist system autonomously developed a physical model explaining previously unpublished experimental observations in α-RuCl₃, a candidate material for realizing a Kitaev quan...

Security AI
Security AI

Proofpoint links TA419 phishing campaigns to US AI policy targets

Proofpoint has attributed credential phishing campaigns against U.S. AI experts at think tanks, universities and legal organizations to TA419, a group it describes as China-aligned and motivated by espionage. Its analysis describe...

Security
Security

FortiMail flaw faces active exploitation while fixes remain unavailable

Fortinet says attackers are exploiting CVE-2026-104286 in FortiMail, with no fixed build yet available across affected release branches. The vulnerability lets an attacker without authentication send crafted HTTP or HTTPS requests...