{"id":5956,"date":"2026-07-13T18:01:46","date_gmt":"2026-07-13T18:01:46","guid":{"rendered":"https:\/\/securitybriefing.net\/?p=5956"},"modified":"2026-07-23T16:58:57","modified_gmt":"2026-07-23T16:58:57","slug":"cisa-sharepoint-rce-cve-2026-45659-added-to-kev","status":"publish","type":"post","link":"https:\/\/securitybriefing.net\/de\/cyber-warnungen\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/","title":{"rendered":"CISA Adds Actively Exploited SharePoint RCE (CVE-2026-45659) to KEV Catalog"},"content":{"rendered":"<p>On July 1, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Microsoft SharePoint remote code execution flaw to its <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\" rel=\"noopener\">Known Exploited Vulnerabilities (KEV) catalog<\/a>, citing evidence of active exploitation. Tracked as <strong><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-45659\" target=\"_blank\" rel=\"noopener\">CVE-2026-45659<\/a><\/strong> and rated CVSS 8.8, the vulnerability came with an unusually tight remediation window: the Binding Operational Directive deadline for federal agencies was set for July 4, 2026, just three days after listing.<\/p>\n<h2>A deserialization flaw in SharePoint Server<\/h2>\n<p>CVE-2026-45659 is a remote code execution vulnerability caused by deserialization of untrusted data. It affects <strong>SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016<\/strong>. Exploitation requires authenticated access &mdash; but only at the low &#8220;Site Member&#8221; level, with no administrative or elevated privileges needed &mdash; and can be carried out over the network. That low bar is what makes it dangerous: any SharePoint deployment with self-service sign-up or broadly granted membership is a realistic target.<\/p>\n<h2>Patched in May, exploited by July<\/h2>\n<p>Microsoft shipped fixes for the flaw back in May 2026, so organizations that patch promptly are already protected. The risk lives in the gap between patch availability and deployment &mdash; CISA&#8217;s KEV listing means the vulnerability is being exploited in the wild now, roughly two months after the fix was published. Notably, Microsoft&#8217;s own advisory tags the bug with an &#8220;Exploitation Less Likely&#8221; assessment, a useful reminder that vendor exploitability ratings and real-world attacker behavior do not always line up.<\/p>\n<h2>What to do now<\/h2>\n<p>If you run SharePoint Server Subscription Edition, 2019, or Enterprise 2016, apply Microsoft&#8217;s May 2026 security updates immediately if you have not already. SharePoint has been a repeated target for ransomware crews and state-linked actors, and an authenticated RCE that needs only Site Member access is exactly the kind of foothold those groups look for. Review who holds membership on internet-facing SharePoint sites, tighten self-registration, and closely monitor any server that stayed unpatched after May for signs of compromise.<\/p>","protected":false},"excerpt":{"rendered":"<p>CISA added the actively exploited SharePoint RCE flaw CVE-2026-45659 (CVSS 8.8) to its KEV catalog, with a July 4 federal patch deadline.<\/p>","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[40],"tags":[],"class_list":["post-5956","post","type-post","status-publish","format-standard","hentry","category-cyber-alerts","entry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CISA Adds Exploited SharePoint RCE CVE-2026-45659 to KEV<\/title>\n<meta name=\"description\" content=\"CISA added SharePoint RCE CVE-2026-45659 (CVSS 8.8) to its KEV catalog after active exploitation.\" \/>\n<meta name=\"robots\" content=\"noindex, follow\" \/>\n<meta property=\"og:locale\" content=\"de_DE\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CISA Adds Exploited SharePoint RCE CVE-2026-45659 to KEV\" \/>\n<meta property=\"og:description\" content=\"CISA added SharePoint RCE CVE-2026-45659 (CVSS 8.8) to its KEV catalog after active exploitation.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/securitybriefing.net\/de\/cyber-warnungen\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/\" \/>\n<meta property=\"og:site_name\" content=\"Security Briefing\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-13T18:01:46+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-23T16:58:57+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/securitybriefing.net\/wp-content\/uploads\/2025\/09\/main-logo-black.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"300\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"C\u00e9sar Daniel Barreto\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Geschrieben von\" \/>\n\t<meta name=\"twitter:data1\" content=\"C\u00e9sar Daniel Barreto\" \/>\n\t<meta name=\"twitter:label2\" content=\"Gesch\u00e4tzte Lesezeit\" \/>\n\t<meta name=\"twitter:data2\" content=\"2\u00a0Minuten\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/\"},\"author\":{\"name\":\"C\u00e9sar Daniel Barreto\",\"@id\":\"https:\/\/securitybriefing.net\/#\/schema\/person\/e1c50274ae765e23bb826bbca980e166\"},\"headline\":\"CISA Adds Actively Exploited SharePoint RCE (CVE-2026-45659) to KEV Catalog\",\"datePublished\":\"2026-07-13T18:01:46+00:00\",\"dateModified\":\"2026-07-23T16:58:57+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/\"},\"wordCount\":326,\"publisher\":{\"@id\":\"https:\/\/securitybriefing.net\/#organization\"},\"articleSection\":[\"cyber alerts\"],\"inLanguage\":\"de\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/\",\"url\":\"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/\",\"name\":\"CISA Adds Exploited SharePoint RCE CVE-2026-45659 to KEV\",\"isPartOf\":{\"@id\":\"https:\/\/securitybriefing.net\/#website\"},\"datePublished\":\"2026-07-13T18:01:46+00:00\",\"dateModified\":\"2026-07-23T16:58:57+00:00\",\"description\":\"CISA added SharePoint RCE CVE-2026-45659 (CVSS 8.8) to its KEV catalog after active exploitation.\",\"breadcrumb\":{\"@id\":\"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/#breadcrumb\"},\"inLanguage\":\"de\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/securitybriefing.net\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"cyber alerts\",\"item\":\"https:\/\/securitybriefing.net\/cyber-alerts\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"CISA Adds Actively Exploited SharePoint RCE (CVE-2026-45659) to KEV Catalog\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/securitybriefing.net\/#website\",\"url\":\"https:\/\/securitybriefing.net\/\",\"name\":\"Security Briefing\",\"description\":\"Read cybersecurity news, online safety guides, cyber threat updates, and use free security tools from Security Briefing.\",\"publisher\":{\"@id\":\"https:\/\/securitybriefing.net\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/securitybriefing.net\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"de\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/securitybriefing.net\/#organization\",\"name\":\"Security Briefing\",\"url\":\"https:\/\/securitybriefing.net\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"de\",\"@id\":\"https:\/\/securitybriefing.net\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/securitybriefing.net\/wp-content\/uploads\/2023\/06\/security-briefing-logo-5.png\",\"contentUrl\":\"https:\/\/securitybriefing.net\/wp-content\/uploads\/2023\/06\/security-briefing-logo-5.png\",\"width\":256,\"height\":70,\"caption\":\"Security Briefing\"},\"image\":{\"@id\":\"https:\/\/securitybriefing.net\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/securitybriefing.net\/#\/schema\/person\/e1c50274ae765e23bb826bbca980e166\",\"name\":\"C\u00e9sar Daniel Barreto\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"de\",\"@id\":\"https:\/\/securitybriefing.net\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/9e709cab74f02e628ffc32849980d0ea51903be7d4bcb52e99250bac60f0b683?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/9e709cab74f02e628ffc32849980d0ea51903be7d4bcb52e99250bac60f0b683?s=96&d=mm&r=g\",\"caption\":\"C\u00e9sar Daniel Barreto\"},\"description\":\"C\u00e9sar Daniel Barreto is an esteemed cybersecurity writer and expert, known for his in-depth knowledge and ability to simplify complex cyber security topics. With extensive experience in network security and data protection, he regularly contributes insightful articles and analysis on the latest cybersecurity trends, educating both professionals and the public.\",\"url\":\"https:\/\/securitybriefing.net\/de\/author\/cesarbarreto\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CISA Adds Exploited SharePoint RCE CVE-2026-45659 to KEV","description":"CISA added SharePoint RCE CVE-2026-45659 (CVSS 8.8) to its KEV catalog after active exploitation.","robots":{"index":"noindex","follow":"follow"},"og_locale":"de_DE","og_type":"article","og_title":"CISA Adds Exploited SharePoint RCE CVE-2026-45659 to KEV","og_description":"CISA added SharePoint RCE CVE-2026-45659 (CVSS 8.8) to its KEV catalog after active exploitation.","og_url":"https:\/\/securitybriefing.net\/de\/cyber-warnungen\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/","og_site_name":"Security Briefing","article_published_time":"2026-07-13T18:01:46+00:00","article_modified_time":"2026-07-23T16:58:57+00:00","og_image":[{"width":1200,"height":300,"url":"https:\/\/securitybriefing.net\/wp-content\/uploads\/2025\/09\/main-logo-black.png","type":"image\/png"}],"author":"C\u00e9sar Daniel Barreto","twitter_card":"summary_large_image","twitter_misc":{"Geschrieben von":"C\u00e9sar Daniel Barreto","Gesch\u00e4tzte Lesezeit":"2\u00a0Minuten"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/#article","isPartOf":{"@id":"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/"},"author":{"name":"C\u00e9sar Daniel Barreto","@id":"https:\/\/securitybriefing.net\/#\/schema\/person\/e1c50274ae765e23bb826bbca980e166"},"headline":"CISA Adds Actively Exploited SharePoint RCE (CVE-2026-45659) to KEV Catalog","datePublished":"2026-07-13T18:01:46+00:00","dateModified":"2026-07-23T16:58:57+00:00","mainEntityOfPage":{"@id":"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/"},"wordCount":326,"publisher":{"@id":"https:\/\/securitybriefing.net\/#organization"},"articleSection":["cyber alerts"],"inLanguage":"de"},{"@type":"WebPage","@id":"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/","url":"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/","name":"CISA Adds Exploited SharePoint RCE CVE-2026-45659 to KEV","isPartOf":{"@id":"https:\/\/securitybriefing.net\/#website"},"datePublished":"2026-07-13T18:01:46+00:00","dateModified":"2026-07-23T16:58:57+00:00","description":"CISA added SharePoint RCE CVE-2026-45659 (CVSS 8.8) to its KEV catalog after active exploitation.","breadcrumb":{"@id":"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/#breadcrumb"},"inLanguage":"de","potentialAction":[{"@type":"ReadAction","target":["https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/securitybriefing.net\/"},{"@type":"ListItem","position":2,"name":"cyber alerts","item":"https:\/\/securitybriefing.net\/cyber-alerts\/"},{"@type":"ListItem","position":3,"name":"CISA Adds Actively Exploited SharePoint RCE (CVE-2026-45659) to KEV Catalog"}]},{"@type":"WebSite","@id":"https:\/\/securitybriefing.net\/#website","url":"https:\/\/securitybriefing.net\/","name":"Sicherheitsbriefing","description":"Lesen Sie Cybersicherheitsnachrichten, Online-Sicherheitsleitf\u00e4den, Cyber-Bedrohungsupdates und nutzen Sie kostenlose Sicherheitstools von Security Briefing.","publisher":{"@id":"https:\/\/securitybriefing.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/securitybriefing.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"de"},{"@type":"Organization","@id":"https:\/\/securitybriefing.net\/#organization","name":"Sicherheitsbriefing","url":"https:\/\/securitybriefing.net\/","logo":{"@type":"ImageObject","inLanguage":"de","@id":"https:\/\/securitybriefing.net\/#\/schema\/logo\/image\/","url":"https:\/\/securitybriefing.net\/wp-content\/uploads\/2023\/06\/security-briefing-logo-5.png","contentUrl":"https:\/\/securitybriefing.net\/wp-content\/uploads\/2023\/06\/security-briefing-logo-5.png","width":256,"height":70,"caption":"Security Briefing"},"image":{"@id":"https:\/\/securitybriefing.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/securitybriefing.net\/#\/schema\/person\/e1c50274ae765e23bb826bbca980e166","name":"C\u00e9sar Daniel Barreto","image":{"@type":"ImageObject","inLanguage":"de","@id":"https:\/\/securitybriefing.net\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/9e709cab74f02e628ffc32849980d0ea51903be7d4bcb52e99250bac60f0b683?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9e709cab74f02e628ffc32849980d0ea51903be7d4bcb52e99250bac60f0b683?s=96&d=mm&r=g","caption":"C\u00e9sar Daniel Barreto"},"description":"C\u00e9sar Daniel Barreto ist ein gesch\u00e4tzter Cybersecurity-Autor und -Experte, der f\u00fcr sein fundiertes Wissen und seine F\u00e4higkeit bekannt ist, komplexe Cybersicherheitsthemen zu vereinfachen. Mit seiner umfassenden Erfahrung in den Bereichen Netzwerksicherheit und Datenschutz verfasst er regelm\u00e4\u00dfig aufschlussreiche Artikel und Analysen zu den neuesten Trends in der Cybersicherheit und informiert damit sowohl Fachleute als auch die \u00d6ffentlichkeit.","url":"https:\/\/securitybriefing.net\/de\/author\/cesarbarreto\/"}]}},"_links":{"self":[{"href":"https:\/\/securitybriefing.net\/de\/wp-json\/wp\/v2\/posts\/5956","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/securitybriefing.net\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/securitybriefing.net\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/securitybriefing.net\/de\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/securitybriefing.net\/de\/wp-json\/wp\/v2\/comments?post=5956"}],"version-history":[{"count":1,"href":"https:\/\/securitybriefing.net\/de\/wp-json\/wp\/v2\/posts\/5956\/revisions"}],"predecessor-version":[{"id":6178,"href":"https:\/\/securitybriefing.net\/de\/wp-json\/wp\/v2\/posts\/5956\/revisions\/6178"}],"wp:attachment":[{"href":"https:\/\/securitybriefing.net\/de\/wp-json\/wp\/v2\/media?parent=5956"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/securitybriefing.net\/de\/wp-json\/wp\/v2\/categories?post=5956"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/securitybriefing.net\/de\/wp-json\/wp\/v2\/tags?post=5956"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}