VulnerabilityMicrosoftPatch management

SharePoint Server: CVE-2026-45659 is being exploited—patch now

CISA has added SharePoint vulnerability CVE-2026-45659 to its red list. Here is the real risk to a French SME or mid-sized company, and a 48-hour action plan.

Hakim Djelili7 min read

On July 2, 2026, CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities Catalog. Two days later, the remediation deadline for US federal agencies expired. France has no official deadline, but the message is clear: on-premises SharePoint Server is once again a prime target.

The vulnerability

What CVE-2026-45659 actually allows

The vulnerability stems from unsafe deserialisation of untrusted data. In plain terms, SharePoint accepts objects sent by a user and reconstructs them without checking their contents. An attacker can embed instructions and force the server to execute them with the privileges of the SharePoint service, typically NT AUTHORITY\NETWORK SERVICE or a dedicated service account.

The critical point is that authentication is required, but only with Site Member permissions. In other words, any employee with access to a collaborative workspace. Or any account compromised by phishing the previous week. Or a former contractor whose account was never disabled.

8.8

CVSS score

High severity

May 12, 2026

Patch released by Microsoft

KB5002863, KB5002870, KB5002868

July 2, 2026

Added to the CISA KEV Catalog

Evidence of active exploitation

Scope

Who is actually affected in France

The good news for many SMEs is that if you use Microsoft 365 (SharePoint Online) exclusively, this vulnerability does not affect you. SharePoint servers in Microsoft's cloud have already been updated, and the architecture is different.

The bad news for many mid-sized and industrial companies is that on-premises SharePoint Server remains widespread in two situations.

At risk

You have on-premises SharePoint if...

  • Your legacy intranet portals have never been migrated
  • You have sovereignty requirements (defence, healthcare, sensitive industries)
  • You use business applications that rely on SharePoint
  • You operate a hybrid environment with an on-premises SharePoint instance that synchronises
  • An old SharePoint 2016 or 2019 project is still running without a clear owner

Not affected

You are outside the scope if...

  • All your collaboration takes place in Microsoft 365 / SharePoint Online
  • You use Google Workspace exclusively
  • You do not expose any on-premises SharePoint service to the internet
  • Your old SharePoint servers have been decommissioned

Context

Why this vulnerability matters to SMEs

A compromised SharePoint server is not just a failed intranet. It often means:

  • Access to HR, sales and R&D file repositories
  • A pivot point into the domain's Active Directory
  • A springboard to network shares
  • An ideal gateway for deploying ransomware

Groups such as Akira, RansomHub and Qilin, which were highly active against French targets in 2025–2026, favour this type of vulnerability. The pattern is familiar: exploit an unpatched server CVE, move laterally towards AD within hours, exfiltrate data, then encrypt. According to Cybermalveillance.gouv.fr, the average cost to a French SME remains between €130,000 and €250,000.

Action plan

What to do within 48 hours

  • Identify every on-premises SharePoint server (production, pre-production and forgotten legacy systems)
  • Check the exact version: 2016, 2019 or Subscription Edition
  • Apply patches KB5002863 (Subscription Edition), KB5002870 (2019) or KB5002868 (2016)
  • Restart SharePoint services after applying the patches
  • Audit logs from the past 60 days for abnormal ViewState requests
  • Look for web shells in the layouts and wwwroot directories
  • Review service accounts and recent credential rotations
  • Restrict internet access to the SharePoint server (VPN only, if possible)

Prepare ahead

Two structural habits to establish

One critical CVE a month in a Microsoft product is the norm, not the exception. Two mechanisms protect an SME between disclosures:

  • An up-to-date inventory of exposed software and versions. Without one, you will never know whether the next vulnerability affects you. A simple spreadsheet maintained by your IT department or service provider is enough.
  • A defined patch management cycle. Someone is accountable, a maximum deadline is set (48 hours for exploited critical CVEs and one week for critical CVEs that are not being exploited), and the follow-up is documented.
  1. May 12, 2026

    Microsoft patches released

    KB5002863, KB5002870 and KB5002868 for the three supported versions.

  2. May 26, 2026

    Public proof of concept

    The first exploitation attempts are detected a few days later.

  3. July 2, 2026

    Added to the CISA KEV Catalog

    Official confirmation of widespread active exploitation.

  4. July 4, 2026

    CISA deadline for federal agencies

    A strong warning to every organisation using on-premises SharePoint.

  5. This week

    Action window for French SMEs and mid-sized companies

    Patch immediately, audit access and hunt for signs of compromise.

If you want a quick assessment of your exposure to critical Microsoft CVEs, request a free patch management audit: 30 minutes to identify your blind spots and forgotten servers.

Need a second opinion?

Let's talk for 30 minutes — no commitment

A direct conversation with a senior consultant to frame your cybersecurity priorities and clarify your obligations.

Book a call