🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.

Microsoft SharePoint Server Deserialization RCE (CVE-2026-45659) | MSSP Advisory

Critical🔴 KEV ALERTConfirmed
DateJuly 1, 2026
CVECVE-2026-45659
Risk Assessment
Client Exposure:High
Briefing Priority:Immediate
Barrier to Entry:Low
📋Executive Summary
CISA has added CVE-2026-45659, a Microsoft SharePoint Server deserialization vulnerability, to the Known Exploited Vulnerabilities catalog, meaning active exploitation is already underway in the wild. An authenticated attacker can execute arbitrary code remotely, which in a SharePoint environment often means access to file stores, internal communications, and credentials that open doors deeper into a network. The July 4 patch deadline is a compliance floor, not a safety target.
⚠️Why It Matters for MSSPs
If any of your clients run on-premises SharePoint Server, you have an obligation to notify them today, not at your next scheduled check-in, because code execution on SharePoint translates directly to lateral movement opportunities across the rest of their environment. Your own stack is also at risk if you use SharePoint internally for documentation, runbooks, or client-facing portals, since a compromised MSSP SharePoint instance exposes every credential and process document your team has stored there.
Recommended Action
In the next 24 hours, pull a complete inventory of every SharePoint Server instance across your client base and your own internal environment, then confirm patch status against Microsoft's guidance and flag any unpatched instance as an active incident risk requiring immediate escalation. Send a direct written notification to every affected client today so your advisory obligation is documented, timestamped, and on record before any exploitation event occurs.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Vulnerability Disclosure

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.