Microsoft SharePoint Deserialization RCE | MSSP Advisory
Critical
DateMay 26, 2026
📋Executive Summary
Microsoft patched CVE-2026-45659, a remote code execution vulnerability in SharePoint with a CVSS score of 8.8 that stems from deserialization of untrusted data. The flaw requires no special conditions for exploitation, meaning any authenticated user can potentially execute arbitrary code on SharePoint servers. Microsoft rates this as important severity and has released patches across multiple SharePoint Server versions.
⚠️Why It Matters for MSSPs
Your clients running SharePoint on-premises are sitting ducks until patched, and this vulnerability gives attackers a direct path to domain admin through SharePoint service accounts. SharePoint environments in your client base likely contain sensitive business data and often run with elevated privileges that make this a fast track to full network compromise. Your advisory obligation kicks in immediately because clients expect you to flag critical patches that protect their collaboration platforms.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Vulnerability Disclosure
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.