Critical Microsoft SharePoint Server CVE-2023-29357 Allows Remote Code Execution
Key Takeaways A critical remote code execution (RCE) vulnerability, CVE-2026-45659, has been identified in Microsoft SharePoint Server. The flaw allows authenticated attackers with minimal...
Key Takeaways
- A critical remote code execution (RCE) vulnerability, CVE-2026-45659, has been identified in Microsoft SharePoint Server.
- The flaw allows authenticated attackers with minimal permissions (Site Member level) to execute arbitrary code.
- Affected versions include SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016.
- Microsoft released security updates on May 21, 2026, and immediate patching is strongly recommended.
Microsoft has disclosed a severe security vulnerability impacting its SharePoint Server platform, enabling authenticated attackers to achieve remote code execution (RCE). This critical flaw, identified as CVE-2026-45659, presents a significant risk to organizations utilizing on-premises SharePoint deployments and was publicly announced on May 21, 2026.
Table Of Content
The core of the vulnerability lies in the deserialization of untrusted data within Microsoft Office SharePoint. Exploiting this weakness allows an attacker to execute arbitrary code remotely on the compromised server over a network connection.
Despite Microsoft’s assessment classifying the flaw as “Important” in severity and its exploitation as “Less Likely,” the ease of exploitation makes it a substantial threat demanding immediate attention. The low complexity of the attack vector means that an attacker does not require extensive knowledge of the target system to achieve reliable and repeatable exploitation from the internet.
A particularly troubling aspect of this vulnerability is its low barrier to entry. Any authenticated user holding at least Site Member-level permissions can trigger the exploit, meaning no administrative or elevated privileges are necessary to compromise the server.
The attack vector is network-based (AV:N), and the attack complexity is low (AC:L). This combination signifies that an attacker can launch the exploit across the network with minimal effort, making it highly accessible to potential adversaries.
Affected Versions and Patches
Microsoft has issued security updates for all impacted SharePoint Server versions. Organizations are urged to prioritize the immediate application of these patches.
| Product | KB Article | Build Number |
|---|---|---|
| SharePoint Server Subscription Edition | KB 5002863 | 16.0.19725.20280 |
| SharePoint Server 2019 | KB 5002870 | 16.0.10417.20128 |
| SharePoint Enterprise Server 2016 | KB 5002868 | 16.0.5552.1002 |
While Microsoft currently states there is no evidence of public disclosure or active exploitation of this vulnerability, its low complexity and network accessibility make it a prime target for future exploitation once proof-of-concept code inevitably emerges. Organizations that rely on SharePoint for critical functions such as internal collaboration, document management, or external portals face heightened exposure if patching is delayed. Cybersecurity teams are strongly advised to treat this as a high-priority patching event within their upcoming maintenance windows.
What You Should Do
- Apply the May 21, 2026, security updates for all affected SharePoint versions without delay, either through the Microsoft Update Catalog or direct download.
- Conduct an audit of site membership permissions and restrict Site Member access to only trusted and necessary users.
- Actively monitor SharePoint Server logs for any anomalous deserialization activity or suspicious code execution attempts.
- Isolate any internet-facing SharePoint instances from the public network until all necessary patches have been confirmed as successfully applied.
- Consider implementing Web Application Firewall (WAF) rules designed to detect and block malicious deserialization payloads.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.