CVE-2026-45659 — Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
- CVSS
- 8.8 (High)
- KEV status
- CISA KEV — Listed
- First seen (CISA KEV)
- Recommended change window
- Emergency change — treat as part of the July 2026 SharePoint patch cluster; do not split the deployment.
- Affected products
- Microsoft SharePoint Server
Why this one matters to a CAB
The third SharePoint entry in the July 2026 KEV cluster is an authorized-user deserialization RCE. The privilege bar is lower than a full unauth bug, but the impact is identical once an attacker has any authenticated account — including a compromised service account or an over-permissioned intranet user.
Defender’s angle
- Least-privilege audit for service accounts: any account that can authenticate to SharePoint should be reviewed. This CVE is a reminder that “authenticated” is not a strong containment boundary.
- Cluster the change window: bundle with CVE-2026-58644 and CVE-2026-56164 as a single July 2026 SharePoint patch wave. One outage window, one comm, one rollback plan.
- Post-patch smoke test: SharePoint updates occasionally regress the People Picker or the Search service. Include a smoke-test checklist in the change record.
What to bring to CAB
Refer to the cluster change record from CVE-2026-58644 and add this CVE to the scope. Do not draft a separate change record — that creates two outage windows for the same farm.
Sources
This page summarizes publicly available information from CISA KEV, NVD, and the listed vendor advisory. Change Risk Intel does not publish exploit walkthroughs. Verify with your vendor before scheduling any change window.