CISA Flags Actively Exploited SharePoint RCE (CVE-2026-45659): What Organizations Need to Know Now
CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog on July 1, 2026, confirming that a high-severity remote code execution flaw in Microsoft SharePoint Server is being actively exploited in the wild. The vulnerability carries a CVSS score of 8.8 and allows any authenticated attacker with Site Member permissions to execute arbitrary code on the


