{"id":5956,"date":"2026-07-13T18:01:46","date_gmt":"2026-07-13T18:01:46","guid":{"rendered":"https:\/\/securitybriefing.net\/?p=5956"},"modified":"2026-07-23T16:58:57","modified_gmt":"2026-07-23T16:58:57","slug":"cisa-sharepoint-rce-cve-2026-45659-added-to-kev","status":"publish","type":"post","link":"https:\/\/securitybriefing.net\/hu\/kiberfigyelmeztetesek\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/","title":{"rendered":"CISA Adds Actively Exploited SharePoint RCE (CVE-2026-45659) to KEV Catalog"},"content":{"rendered":"<p>On July 1, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Microsoft SharePoint remote code execution flaw to its <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\" rel=\"noopener\">Known Exploited Vulnerabilities (KEV) catalog<\/a>, citing evidence of active exploitation. Tracked as <strong><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-45659\" target=\"_blank\" rel=\"noopener\">CVE-2026-45659<\/a><\/strong> and rated CVSS 8.8, the vulnerability came with an unusually tight remediation window: the Binding Operational Directive deadline for federal agencies was set for July 4, 2026, just three days after listing.<\/p>\n<h2>A deserialization flaw in SharePoint Server<\/h2>\n<p>CVE-2026-45659 is a remote code execution vulnerability caused by deserialization of untrusted data. It affects <strong>SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016<\/strong>. Exploitation requires authenticated access &mdash; but only at the low &#8220;Site Member&#8221; level, with no administrative or elevated privileges needed &mdash; and can be carried out over the network. That low bar is what makes it dangerous: any SharePoint deployment with self-service sign-up or broadly granted membership is a realistic target.<\/p>\n<h2>Patched in May, exploited by July<\/h2>\n<p>Microsoft shipped fixes for the flaw back in May 2026, so organizations that patch promptly are already protected. The risk lives in the gap between patch availability and deployment &mdash; CISA&#8217;s KEV listing means the vulnerability is being exploited in the wild now, roughly two months after the fix was published. Notably, Microsoft&#8217;s own advisory tags the bug with an &#8220;Exploitation Less Likely&#8221; assessment, a useful reminder that vendor exploitability ratings and real-world attacker behavior do not always line up.<\/p>\n<h2>What to do now<\/h2>\n<p>If you run SharePoint Server Subscription Edition, 2019, or Enterprise 2016, apply Microsoft&#8217;s May 2026 security updates immediately if you have not already. SharePoint has been a repeated target for ransomware crews and state-linked actors, and an authenticated RCE that needs only Site Member access is exactly the kind of foothold those groups look for. Review who holds membership on internet-facing SharePoint sites, tighten self-registration, and closely monitor any server that stayed unpatched after May for signs of compromise.<\/p>","protected":false},"excerpt":{"rendered":"<p>CISA added the actively exploited SharePoint RCE flaw CVE-2026-45659 (CVSS 8.8) to its KEV catalog, with a July 4 federal patch deadline.<\/p>","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[40],"tags":[],"class_list":["post-5956","post","type-post","status-publish","format-standard","hentry","category-cyber-alerts","entry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CISA Adds Exploited SharePoint RCE CVE-2026-45659 to KEV<\/title>\n<meta name=\"description\" content=\"CISA added SharePoint RCE CVE-2026-45659 (CVSS 8.8) to its KEV catalog after active exploitation.\" \/>\n<meta name=\"robots\" content=\"noindex, follow\" \/>\n<meta property=\"og:locale\" content=\"hu_HU\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CISA Adds Exploited SharePoint RCE CVE-2026-45659 to KEV\" \/>\n<meta property=\"og:description\" content=\"CISA added SharePoint RCE CVE-2026-45659 (CVSS 8.8) to its KEV catalog after active exploitation.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/securitybriefing.net\/hu\/kiberfigyelmeztetesek\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/\" \/>\n<meta property=\"og:site_name\" content=\"Security Briefing\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-13T18:01:46+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-23T16:58:57+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/securitybriefing.net\/wp-content\/uploads\/2025\/09\/main-logo-black.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"300\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"C\u00e9sar Daniel Barreto\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Szerz\u0151:\" \/>\n\t<meta name=\"twitter:data1\" content=\"C\u00e9sar Daniel Barreto\" \/>\n\t<meta name=\"twitter:label2\" content=\"Becs\u00fclt olvas\u00e1si id\u0151\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 perc\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/\"},\"author\":{\"name\":\"C\u00e9sar Daniel Barreto\",\"@id\":\"https:\/\/securitybriefing.net\/#\/schema\/person\/e1c50274ae765e23bb826bbca980e166\"},\"headline\":\"CISA Adds Actively Exploited SharePoint RCE (CVE-2026-45659) to KEV Catalog\",\"datePublished\":\"2026-07-13T18:01:46+00:00\",\"dateModified\":\"2026-07-23T16:58:57+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/\"},\"wordCount\":326,\"publisher\":{\"@id\":\"https:\/\/securitybriefing.net\/#organization\"},\"articleSection\":[\"cyber alerts\"],\"inLanguage\":\"hu\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/\",\"url\":\"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/\",\"name\":\"CISA Adds Exploited SharePoint RCE CVE-2026-45659 to KEV\",\"isPartOf\":{\"@id\":\"https:\/\/securitybriefing.net\/#website\"},\"datePublished\":\"2026-07-13T18:01:46+00:00\",\"dateModified\":\"2026-07-23T16:58:57+00:00\",\"description\":\"CISA added SharePoint RCE CVE-2026-45659 (CVSS 8.8) to its KEV catalog after active exploitation.\",\"breadcrumb\":{\"@id\":\"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/#breadcrumb\"},\"inLanguage\":\"hu\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/securitybriefing.net\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"cyber alerts\",\"item\":\"https:\/\/securitybriefing.net\/cyber-alerts\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"CISA Adds Actively Exploited SharePoint RCE (CVE-2026-45659) to KEV Catalog\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/securitybriefing.net\/#website\",\"url\":\"https:\/\/securitybriefing.net\/\",\"name\":\"Security Briefing\",\"description\":\"Read cybersecurity news, online safety guides, cyber threat updates, and use free security tools from Security Briefing.\",\"publisher\":{\"@id\":\"https:\/\/securitybriefing.net\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/securitybriefing.net\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"hu\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/securitybriefing.net\/#organization\",\"name\":\"Security Briefing\",\"url\":\"https:\/\/securitybriefing.net\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"hu\",\"@id\":\"https:\/\/securitybriefing.net\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/securitybriefing.net\/wp-content\/uploads\/2023\/06\/security-briefing-logo-5.png\",\"contentUrl\":\"https:\/\/securitybriefing.net\/wp-content\/uploads\/2023\/06\/security-briefing-logo-5.png\",\"width\":256,\"height\":70,\"caption\":\"Security Briefing\"},\"image\":{\"@id\":\"https:\/\/securitybriefing.net\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/securitybriefing.net\/#\/schema\/person\/e1c50274ae765e23bb826bbca980e166\",\"name\":\"C\u00e9sar Daniel Barreto\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"hu\",\"@id\":\"https:\/\/securitybriefing.net\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/9e709cab74f02e628ffc32849980d0ea51903be7d4bcb52e99250bac60f0b683?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/9e709cab74f02e628ffc32849980d0ea51903be7d4bcb52e99250bac60f0b683?s=96&d=mm&r=g\",\"caption\":\"C\u00e9sar Daniel Barreto\"},\"description\":\"C\u00e9sar Daniel Barreto is an esteemed cybersecurity writer and expert, known for his in-depth knowledge and ability to simplify complex cyber security topics. With extensive experience in network security and data protection, he regularly contributes insightful articles and analysis on the latest cybersecurity trends, educating both professionals and the public.\",\"url\":\"https:\/\/securitybriefing.net\/hu\/author\/cesarbarreto\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CISA Adds Exploited SharePoint RCE CVE-2026-45659 to KEV","description":"CISA added SharePoint RCE CVE-2026-45659 (CVSS 8.8) to its KEV catalog after active exploitation.","robots":{"index":"noindex","follow":"follow"},"og_locale":"hu_HU","og_type":"article","og_title":"CISA Adds Exploited SharePoint RCE CVE-2026-45659 to KEV","og_description":"CISA added SharePoint RCE CVE-2026-45659 (CVSS 8.8) to its KEV catalog after active exploitation.","og_url":"https:\/\/securitybriefing.net\/hu\/kiberfigyelmeztetesek\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/","og_site_name":"Security Briefing","article_published_time":"2026-07-13T18:01:46+00:00","article_modified_time":"2026-07-23T16:58:57+00:00","og_image":[{"width":1200,"height":300,"url":"https:\/\/securitybriefing.net\/wp-content\/uploads\/2025\/09\/main-logo-black.png","type":"image\/png"}],"author":"C\u00e9sar Daniel Barreto","twitter_card":"summary_large_image","twitter_misc":{"Szerz\u0151:":"C\u00e9sar Daniel Barreto","Becs\u00fclt olvas\u00e1si id\u0151":"2 perc"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/#article","isPartOf":{"@id":"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/"},"author":{"name":"C\u00e9sar Daniel Barreto","@id":"https:\/\/securitybriefing.net\/#\/schema\/person\/e1c50274ae765e23bb826bbca980e166"},"headline":"CISA Adds Actively Exploited SharePoint RCE (CVE-2026-45659) to KEV Catalog","datePublished":"2026-07-13T18:01:46+00:00","dateModified":"2026-07-23T16:58:57+00:00","mainEntityOfPage":{"@id":"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/"},"wordCount":326,"publisher":{"@id":"https:\/\/securitybriefing.net\/#organization"},"articleSection":["cyber alerts"],"inLanguage":"hu"},{"@type":"WebPage","@id":"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/","url":"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/","name":"CISA Adds Exploited SharePoint RCE CVE-2026-45659 to KEV","isPartOf":{"@id":"https:\/\/securitybriefing.net\/#website"},"datePublished":"2026-07-13T18:01:46+00:00","dateModified":"2026-07-23T16:58:57+00:00","description":"CISA added SharePoint RCE CVE-2026-45659 (CVSS 8.8) to its KEV catalog after active exploitation.","breadcrumb":{"@id":"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/#breadcrumb"},"inLanguage":"hu","potentialAction":[{"@type":"ReadAction","target":["https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/securitybriefing.net\/cyber-alerts\/cisa-sharepoint-rce-cve-2026-45659-added-to-kev\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/securitybriefing.net\/"},{"@type":"ListItem","position":2,"name":"cyber alerts","item":"https:\/\/securitybriefing.net\/cyber-alerts\/"},{"@type":"ListItem","position":3,"name":"CISA Adds Actively Exploited SharePoint RCE (CVE-2026-45659) to KEV Catalog"}]},{"@type":"WebSite","@id":"https:\/\/securitybriefing.net\/#website","url":"https:\/\/securitybriefing.net\/","name":"Biztons\u00e1gi t\u00e1j\u00e9koztat\u00f3","description":"Olvasson kiberbiztons\u00e1gi h\u00edreket, online biztons\u00e1gi \u00fatmutat\u00f3kat, kiberfenyeget\u00e9sekkel kapcsolatos friss\u00edt\u00e9seket, \u00e9s haszn\u00e1ljon ingyenes biztons\u00e1gi eszk\u00f6z\u00f6ket a Security Briefing oldalr\u00f3l.","publisher":{"@id":"https:\/\/securitybriefing.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/securitybriefing.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"hu"},{"@type":"Organization","@id":"https:\/\/securitybriefing.net\/#organization","name":"Biztons\u00e1gi t\u00e1j\u00e9koztat\u00f3","url":"https:\/\/securitybriefing.net\/","logo":{"@type":"ImageObject","inLanguage":"hu","@id":"https:\/\/securitybriefing.net\/#\/schema\/logo\/image\/","url":"https:\/\/securitybriefing.net\/wp-content\/uploads\/2023\/06\/security-briefing-logo-5.png","contentUrl":"https:\/\/securitybriefing.net\/wp-content\/uploads\/2023\/06\/security-briefing-logo-5.png","width":256,"height":70,"caption":"Security Briefing"},"image":{"@id":"https:\/\/securitybriefing.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/securitybriefing.net\/#\/schema\/person\/e1c50274ae765e23bb826bbca980e166","name":"C\u00e9sar D\u00e1niel Barreto","image":{"@type":"ImageObject","inLanguage":"hu","@id":"https:\/\/securitybriefing.net\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/9e709cab74f02e628ffc32849980d0ea51903be7d4bcb52e99250bac60f0b683?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9e709cab74f02e628ffc32849980d0ea51903be7d4bcb52e99250bac60f0b683?s=96&d=mm&r=g","caption":"C\u00e9sar Daniel Barreto"},"description":"C\u00e9sar Daniel Barreto elismert kiberbiztons\u00e1gi \u00edr\u00f3 \u00e9s szak\u00e9rt\u0151, aki m\u00e9lyrehat\u00f3 tud\u00e1s\u00e1r\u00f3l \u00e9s k\u00e9pess\u00e9g\u00e9r\u0151l ismert, hogy egyszer\u0171s\u00edtse a bonyolult kiberbiztons\u00e1gi t\u00e9m\u00e1kat. Kiterjedt h\u00e1l\u00f3zatbiztons\u00e1gi \u00e9s adatv\u00e9delmi tapasztalattal rendelkezik, rendszeresen k\u00f6z\u00f6l betekint\u0151 cikkeket \u00e9s elemz\u00e9seket a leg\u00fajabb kiberbiztons\u00e1gi trendekr\u0151l, oktatva mind a szakembereket, mind a nagyk\u00f6z\u00f6ns\u00e9get.","url":"https:\/\/securitybriefing.net\/hu\/author\/cesarbarreto\/"}]}},"_links":{"self":[{"href":"https:\/\/securitybriefing.net\/hu\/wp-json\/wp\/v2\/posts\/5956","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/securitybriefing.net\/hu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/securitybriefing.net\/hu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/securitybriefing.net\/hu\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/securitybriefing.net\/hu\/wp-json\/wp\/v2\/comments?post=5956"}],"version-history":[{"count":1,"href":"https:\/\/securitybriefing.net\/hu\/wp-json\/wp\/v2\/posts\/5956\/revisions"}],"predecessor-version":[{"id":6178,"href":"https:\/\/securitybriefing.net\/hu\/wp-json\/wp\/v2\/posts\/5956\/revisions\/6178"}],"wp:attachment":[{"href":"https:\/\/securitybriefing.net\/hu\/wp-json\/wp\/v2\/media?parent=5956"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/securitybriefing.net\/hu\/wp-json\/wp\/v2\/categories?post=5956"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/securitybriefing.net\/hu\/wp-json\/wp\/v2\/tags?post=5956"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}