CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog on July 1, 2026, after confirming attackers are using the SharePoint Server remote-code-execution flaw for initial access and ransomware deployment. Although Microsoft patched the underlying deserialization bug in May 2026, the active exploitation necessitates immediate remediation. Federal agencies were directed to address the vulnerability by July 4, 2026.

Relevant URL: https://www.theregister.com/security/2026/07/02/microsoft-said-exploitation-was-less-likely-but-cisa-just-added-sharepoint-rce-to-kev-list/5265886