On July 2, 2026, CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities Catalog. Two days later, the remediation deadline for US federal agencies expired. France has no official deadline, but the message is clear: on-premises SharePoint Server is once again a prime target.
The vulnerability
What CVE-2026-45659 actually allows
The vulnerability stems from unsafe deserialisation of untrusted data. In plain terms, SharePoint accepts objects sent by a user and reconstructs them without checking their contents. An attacker can embed instructions and force the server to execute them with the privileges of the SharePoint service, typically NT AUTHORITY\NETWORK SERVICE or a dedicated service account.
The critical point is that authentication is required, but only with Site Member permissions. In other words, any employee with access to a collaborative workspace. Or any account compromised by phishing the previous week. Or a former contractor whose account was never disabled.
8.8
CVSS score
High severity
May 12, 2026
Patch released by Microsoft
KB5002863, KB5002870, KB5002868
July 2, 2026
Added to the CISA KEV Catalog
Evidence of active exploitation
Scope
Who is actually affected in France
The good news for many SMEs is that if you use Microsoft 365 (SharePoint Online) exclusively, this vulnerability does not affect you. SharePoint servers in Microsoft's cloud have already been updated, and the architecture is different.
The bad news for many mid-sized and industrial companies is that on-premises SharePoint Server remains widespread in two situations.
At risk
You have on-premises SharePoint if...
- Your legacy intranet portals have never been migrated
- You have sovereignty requirements (defence, healthcare, sensitive industries)
- You use business applications that rely on SharePoint
- You operate a hybrid environment with an on-premises SharePoint instance that synchronises
- An old SharePoint 2016 or 2019 project is still running without a clear owner
Not affected
You are outside the scope if...
- All your collaboration takes place in Microsoft 365 / SharePoint Online
- You use Google Workspace exclusively
- You do not expose any on-premises SharePoint service to the internet
- Your old SharePoint servers have been decommissioned
Context
Why this vulnerability matters to SMEs
A compromised SharePoint server is not just a failed intranet. It often means:
- Access to HR, sales and R&D file repositories
- A pivot point into the domain's Active Directory
- A springboard to network shares
- An ideal gateway for deploying ransomware
Groups such as Akira, RansomHub and Qilin, which were highly active against French targets in 2025–2026, favour this type of vulnerability. The pattern is familiar: exploit an unpatched server CVE, move laterally towards AD within hours, exfiltrate data, then encrypt. According to Cybermalveillance.gouv.fr, the average cost to a French SME remains between €130,000 and €250,000.
Action plan
What to do within 48 hours
- Identify every on-premises SharePoint server (production, pre-production and forgotten legacy systems)
- Check the exact version: 2016, 2019 or Subscription Edition
- Apply patches KB5002863 (Subscription Edition), KB5002870 (2019) or KB5002868 (2016)
- Restart SharePoint services after applying the patches
- Audit logs from the past 60 days for abnormal ViewState requests
- Look for web shells in the layouts and wwwroot directories
- Review service accounts and recent credential rotations
- Restrict internet access to the SharePoint server (VPN only, if possible)
Prepare ahead
Two structural habits to establish
One critical CVE a month in a Microsoft product is the norm, not the exception. Two mechanisms protect an SME between disclosures:
- An up-to-date inventory of exposed software and versions. Without one, you will never know whether the next vulnerability affects you. A simple spreadsheet maintained by your IT department or service provider is enough.
- A defined patch management cycle. Someone is accountable, a maximum deadline is set (48 hours for exploited critical CVEs and one week for critical CVEs that are not being exploited), and the follow-up is documented.
May 12, 2026
Microsoft patches released
KB5002863, KB5002870 and KB5002868 for the three supported versions.
May 26, 2026
Public proof of concept
The first exploitation attempts are detected a few days later.
July 2, 2026
Added to the CISA KEV Catalog
Official confirmation of widespread active exploitation.
July 4, 2026
CISA deadline for federal agencies
A strong warning to every organisation using on-premises SharePoint.
This week
Action window for French SMEs and mid-sized companies
Patch immediately, audit access and hunt for signs of compromise.
If you want a quick assessment of your exposure to critical Microsoft CVEs, request a free patch management audit: 30 minutes to identify your blind spots and forgotten servers.
Let's talk for 30 minutes — no commitment
A direct conversation with a senior consultant to frame your cybersecurity priorities and clarify your obligations.
Book a call