Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
OpenAI Pauses Astra Model Development to Assess Cybersecurity Risks
August 8, 2026
Critical Linux Kernel SCTP Vulnerability Lets Attackers Gain Root
August 7, 2026
Critical WordPress XSS2Shell Flaw Allows Remote Code Execution
August 7, 2026
Home/CyberSecurity News/Critical Microsoft SharePoint Server CVE-2023-29357 Allows Remote Code Execution
CyberSecurity News

Critical Microsoft SharePoint Server CVE-2023-29357 Allows Remote Code Execution

Key Takeaways A critical remote code execution (RCE) vulnerability, CVE-2026-45659, has been identified in Microsoft SharePoint Server. The flaw allows authenticated attackers with minimal...

Emy Elsamnoudy
Emy Elsamnoudy
May 26, 2026 3 Min Read
64 0

Key Takeaways

  • A critical remote code execution (RCE) vulnerability, CVE-2026-45659, has been identified in Microsoft SharePoint Server.
  • The flaw allows authenticated attackers with minimal permissions (Site Member level) to execute arbitrary code.
  • Affected versions include SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016.
  • Microsoft released security updates on May 21, 2026, and immediate patching is strongly recommended.

Microsoft has disclosed a severe security vulnerability impacting its SharePoint Server platform, enabling authenticated attackers to achieve remote code execution (RCE). This critical flaw, identified as CVE-2026-45659, presents a significant risk to organizations utilizing on-premises SharePoint deployments and was publicly announced on May 21, 2026.

Table Of Content

  • Key Takeaways
  • Affected Versions and Patches
  • What You Should Do

The core of the vulnerability lies in the deserialization of untrusted data within Microsoft Office SharePoint. Exploiting this weakness allows an attacker to execute arbitrary code remotely on the compromised server over a network connection.

Despite Microsoft’s assessment classifying the flaw as “Important” in severity and its exploitation as “Less Likely,” the ease of exploitation makes it a substantial threat demanding immediate attention. The low complexity of the attack vector means that an attacker does not require extensive knowledge of the target system to achieve reliable and repeatable exploitation from the internet.

A particularly troubling aspect of this vulnerability is its low barrier to entry. Any authenticated user holding at least Site Member-level permissions can trigger the exploit, meaning no administrative or elevated privileges are necessary to compromise the server.

The attack vector is network-based (AV:N), and the attack complexity is low (AC:L). This combination signifies that an attacker can launch the exploit across the network with minimal effort, making it highly accessible to potential adversaries.

Affected Versions and Patches

Microsoft has issued security updates for all impacted SharePoint Server versions. Organizations are urged to prioritize the immediate application of these patches.

Product KB Article Build Number
SharePoint Server Subscription Edition KB 5002863 16.0.19725.20280
SharePoint Server 2019 KB 5002870 16.0.10417.20128
SharePoint Enterprise Server 2016 KB 5002868 16.0.5552.1002

While Microsoft currently states there is no evidence of public disclosure or active exploitation of this vulnerability, its low complexity and network accessibility make it a prime target for future exploitation once proof-of-concept code inevitably emerges. Organizations that rely on SharePoint for critical functions such as internal collaboration, document management, or external portals face heightened exposure if patching is delayed. Cybersecurity teams are strongly advised to treat this as a high-priority patching event within their upcoming maintenance windows.

What You Should Do

  • Apply the May 21, 2026, security updates for all affected SharePoint versions without delay, either through the Microsoft Update Catalog or direct download.
  • Conduct an audit of site membership permissions and restrict Site Member access to only trusted and necessary users.
  • Actively monitor SharePoint Server logs for any anomalous deserialization activity or suspicious code execution attempts.
  • Isolate any internet-facing SharePoint instances from the public network until all necessary patches have been confirmed as successfully applied.
  • Consider implementing Web Application Firewall (WAF) rules designed to detect and block malicious deserialization payloads.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityThreatVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Microsoft Defender Now Automatically Isolates Compromised Devices

Next Post

China-Linked Hackers Target Edge Routers with Custom Linux Malware

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Chrome 101 Patches 41 Vulnerabilities, 6 Critical Memory Bugs
August 7, 2026
Patchwork APT Uses Fake PDFs, Chat Apps to Spy on PCs, Android
August 7, 2026
Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accounts
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us