CVE-2026-45659 is a remote code execution flaw in SharePoint caused by deserialisation of untrusted data. It affects SharePoint Enterprise Server 2016, SharePoint Server 2019 and SharePoint Server Subscription Edition.

Microsoft patched it in May 2026. On 11 August 2026, CISA marked it as exploited in ransomware campaigns.

The timeline is the story

WhenWhat
May 2026Patch released
Early July 2026Flagged as actively exploited
1 July 2026Added to CISA's KEV catalog, with a three-day deadline for federal civilian agencies
11 August 2026CISA confirms ransomware use

Three months from patch to ransomware. Six weeks from KEV listing to ransomware.

That interval is roughly the length of one enterprise patch cycle, which is the uncomfortable part. An organisation running a perfectly ordinary quarterly cadence on an internet-facing SharePoint farm was inside the window the whole time.

The exposure numbers

  • Over 8,500 SharePoint servers exposed online
  • Over 200 still unpatched against this flaw

Two hundred out of eight and a half thousand is, in one sense, a good result — better than 97% patched on an internet-facing product three months after a fix.

It is also two hundred organisations with a known, ransomware-weaponised RCE on a system that holds their documents. SharePoint is where the contracts, the HR files and the internal wiki live. There is no such thing as a low-value SharePoint server.

Why it is easy to exploit

CISA's characterisation: the flaw enables low-complexity attacks, because an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.

Repeatable success is the phrase that turns a vulnerability into a commodity. A bug that works differently on each target stays with skilled operators; one that works the same way every time gets scripted and sold, and ends up in ransomware affiliate toolkits. That is what happened here between July and August.

CISA also notes SharePoint's broader record: 14 actively exploited SharePoint vulnerabilities since November 2021, of which 8 were also used in ransomware.

Eight of fourteen. On this product, a KEV listing is closer to a prediction than a warning.

Not to be confused with this month's SharePoint chain

August's Patch Tuesday also closed a SharePoint chain — CVE-2026-55040 (July, authentication bypass) plus CVE-2026-63520 (August, RCE) — which together produced unauthenticated RCE.

Different flaws, same product, same month. If you are triaging SharePoint right now you need all of it: the May patch for CVE-2026-45659, and both the July and August updates for the chain.

What to do

  • Verify the May patch is applied, not scheduled. Check the build, not the ticket.
  • Confirm whether your SharePoint is internet-facing. For most organisations it should not be, and the answer is often a surprise.
  • Assume compromise if you were exposed and unpatched through July. Ransomware use in August means access sold in July.
  • Treat KEV as a deadline, not a feed. The three-day federal requirement exists because the intervals in that table are the norm, not the exception.

The same argument applies here that applied to Kemp LoadMaster reaching KEV and the Cisco FMC zero-day: internet-facing enterprise software gets weaponised on a schedule now, and the schedule is faster than most patch cycles.