
The US Cybersecurity and Infrastructure Security Agency (CISA) has added a serious Microsoft SharePoint Server vulnerability — CVE-2026-45659 — to its list of actively exploited security flaws. The bug allows anyone with a basic SharePoint account (even just a “Site Member” with minimal permissions) to run malicious code on the server without any further help from an administrator. Microsoft released a fix in May 2026, but attackers are now actively scanning for and compromising unpatched servers.
CVSS scoring rates this flaw at 8.8 out of 10 — “High” severity. Federal agencies in the United States had a mandatory deadline of July 4, 2026 to apply the patch. For private businesses, CISA’s guidance is the same: treat this as urgent and apply the update immediately. If your organization uses an on-premises SharePoint server rather than SharePoint Online through Microsoft 365, you need to act now — SharePoint Online is managed by Microsoft and already protected.
How to check if you’re affected
Affected versions include SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016 — all on-premises installations only. SharePoint Online (part of Microsoft 365) is not affected. To check your version, log in as a SharePoint administrator, go to the SharePoint Central Administration site, and click “Upgrade and Migration” → “Check product and patch installation status.” Compare your build number against Microsoft’s May 2026 cumulative update. If you haven’t applied the May 2026 patch, your server is vulnerable.
