DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:12:51ZSOURCES: 14CRITICAL: 31
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — Sampled credentials from the FortiBleed dataset and confirmed they are authentic. Many of… /// @MsftSecIntel CRITICAL — Tracking FortiBleed downstream activity. Buyers of the FortiGate credential sets are… /// @TalosSecurity CRITICAL — FortiBleed is just one piece of a broader IAB operation. The same Russian-speaking actor… /// @MalwareHunterTeam CRITICAL — The Gentlemen RaaS internal data leak (May 2026, ~16GB) confirmed operators actively… /// @CrowdStrike CRITICAL — Gentlemen RaaS affiliates are deploying GentleKiller variants that specifically target…
31Critical Threats
18Active CVEs
19IOCs Tracked
11New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-45659PUBLISHED: 2026-05-26
HIGHCVE-2026-45659

Microsoft SharePoint Server Deserialization RCE

VENDOR: Microsoft//PRODUCT: SharePoint Server (Subscription Edition, 2019, Enterprise Server 2016)
8.8
HIGH
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
NO KNOWN EXPLOIT

Deserialization of untrusted data in Microsoft Office SharePoint allows an authenticated attacker with a minimum of Site Member permissions (low privilege) to execute arbitrary code remotely on a SharePoint Server instance without any user interaction. No PoC is currently publicly available, but SharePoint RCE flaws have historically been weaponized rapidly by ransomware operators, nation-state actors, and initial access brokers. The previous month's SharePoint spoofing flaw (CVE-2026-32201) was actively exploited in the wild.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
LOW
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSSharePoint Server Subscription Edition, SharePoint Server 2019, SharePoint Enterprise Server 2016 (prior to May 2026 CU builds)
  • https://thehackernews.com/2026/05/microsoft-patches-sharepoint-rce-flaw.html
  • https://www.helpnetsecurity.com/2026/05/26/sharepoint-vulnerability-cve-2026-45659/
  • https://msrc.microsoft.com/update-guide/
  • https://vulert.com/blog/cve-2026-45659-microsoft-sharepoint-rce-flaw/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn