// NEXUSVOID CYBER NEWS
<- ALL CYBER NEWS
Critical
Microsoft, SharePoint, KEV, RCE, actively exploited
SharePoint RCE CVE-2026-45659 Is Being Actively Exploited - CISA Says Patch Now
CISA added CVE-2026-45659, a remote code execution flaw in Microsoft SharePoint Server (CVSS 8.8), to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. If you run on-prem SharePoint, this is now a patch-today situation.
When CISA adds a vulnerability to its Known Exploited Vulnerabilities catalog, it is not issuing a warning about something that might happen. It is confirming that attackers are already using the flaw against real targets. Last week a Microsoft SharePoint Server bug, CVE-2026-45659, earned that unwelcome distinction, as reported by The Hacker News.
The vulnerability is a remote code execution flaw rated 8.8 out of 10, and it affects on-premises SharePoint Server, not the SharePoint Online that runs inside Microsoft 365. That distinction matters, because the on-prem estate skews toward larger enterprises, government, and regulated industries, the organizations that kept their collaboration data behind their own walls, and that hold exactly the documents an attacker wants.
A KEV listing also carries a quiet implication about timing. Exploitation almost always precedes the catalog entry, which means the window of exposure opened before the headline did. Our own analysis of the 2025 KEV data found that the median gap between a flaw's disclosure and confirmed exploitation was 26 days, short enough that anything tested on a quarterly or annual cadence would simply never check for this before an attacker reached it.
Apply Microsoft's patch immediately if you run on-prem SharePoint. If you cannot within hours, restrict the server's exposure and watch for anomalous process activity, then review your logs backward on the assumption the window was already open. And if you are entirely on SharePoint Online, this particular flaw does not apply to you.
Sources: The Hacker News and the CISA KEV catalog.