Severity: Critical
Affected Product: Microsoft SharePoint Server (On-Premises)
Affected Audience: Executive Management, IT Operations, Infrastructure Teams, Security Operations, SharePoint Administrators
Executive Summary
An urgent warning has been issued following the active exploitation of multiple vulnerabilities affecting Microsoft SharePoint Server.
These vulnerabilities could allow attackers to execute malicious code, elevate privileges, and gain unauthorized access to SharePoint environments. Because the flaws are already being exploited in real-world attacks, organizations running vulnerable on-premises SharePoint servers should treat this as a high-priority security issue.
SharePoint often stores sensitive corporate documents, project information, intellectual property, and internal business records. If compromised, attackers could steal confidential data, establish persistent access to the network, or use the SharePoint server as a stepping stone to compromise other critical systems.
What Happened?
Microsoft previously released security updates to address a high-severity SharePoint Server vulnerability identified as CVE-2026-45659. However, it has been confirmed that attackers are actively exploiting not just this flaw, but three SharePoint vulnerabilities in attacks targeting internet-facing servers.
Technical Details
The most significant vulnerability is:
- CVE-2026-45659 : Remote Code Execution (RCE)
The vulnerability stems from insecure deserialization, where SharePoint improperly processes specially crafted data supplied by an authenticated user. An attacker with valid credentials can exploit the flaw to execute arbitrary code on the SharePoint server.
The additional vulnerabilities being exploited can be chained together to:
- Escalate privileges
- Execute malicious code
- Bypass security controls
- Maintain persistent access after the initial compromise
Although authentication is required for the primary RCE vulnerability, this should not be viewed as a strong safeguard. Stolen credentials obtained through phishing, password reuse, credential stuffing, or previous compromises are commonly used by attackers to gain authenticated access.
Why This Matters
For many organizations, SharePoint serves as the central hub for collaboration and document management. It often contains:
- Business-critical documents
- Financial records
- HR information
- Contracts
- Internal procedures
- Project documentation
A compromised SharePoint server is more than a document breach, it can provide attackers with a trusted foothold inside the corporate network. From there, they may move laterally to other systems, steal sensitive information, deploy malware, or prepare for ransomware attacks.
Because SharePoint is deeply integrated with Active Directory and other Microsoft services, compromising it can significantly increase the impact of an intrusion.
Potential Business Impact
Successful exploitation could result in:
- Unauthorized access to sensitive corporate information
- Remote execution of malicious code
- Theft of confidential documents
- Installation of malware or ransomware
- Lateral movement to additional systems
- Business disruption and operational downtime
- Regulatory and compliance risks
- Financial and reputational damage
Organizations exposing SharePoint servers directly to the internet face the highest level of risk.
Affected Products
The vulnerabilities affect supported on-premises Microsoft SharePoint Server versions, including:
- SharePoint Server Subscription Edition
- SharePoint Server 2019
- SharePoint Enterprise Server 2016
Organizations should verify that all SharePoint servers have received Microsoft's latest security updates.
SharePoint Online (Microsoft 365) is not impacted.
Recommendations
- Apply Microsoft's latest SharePoint security updates without delay.
- Identify all internet-facing SharePoint servers.
- Review administrator and privileged accounts for unauthorized activity.
- Restrict administrative access to trusted users only.
- Enable Multi-Factor Authentication (MFA) for privileged accounts.

.jpeg)

.jpeg)
.jpeg)

.png)

.png)
.png)