Skip to main content
Change Risk Intel

CVE-2026-45659 — Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.

CVSS
8.8 (High)
KEV status
CISA KEV — Listed
First seen (CISA KEV)
Recommended change window
Emergency change — treat as part of the July 2026 SharePoint patch cluster; do not split the deployment.
Affected products
Microsoft SharePoint Server

Why this one matters to a CAB

The third SharePoint entry in the July 2026 KEV cluster is an authorized-user deserialization RCE. The privilege bar is lower than a full unauth bug, but the impact is identical once an attacker has any authenticated account — including a compromised service account or an over-permissioned intranet user.

Defender’s angle

  • Least-privilege audit for service accounts: any account that can authenticate to SharePoint should be reviewed. This CVE is a reminder that “authenticated” is not a strong containment boundary.
  • Cluster the change window: bundle with CVE-2026-58644 and CVE-2026-56164 as a single July 2026 SharePoint patch wave. One outage window, one comm, one rollback plan.
  • Post-patch smoke test: SharePoint updates occasionally regress the People Picker or the Search service. Include a smoke-test checklist in the change record.

What to bring to CAB

Refer to the cluster change record from CVE-2026-58644 and add this CVE to the scope. Do not draft a separate change record — that creates two outage windows for the same farm.

Sources

This page summarizes publicly available information from CISA KEV, NVD, and the listed vendor advisory. Change Risk Intel does not publish exploit walkthroughs. Verify with your vendor before scheduling any change window.