Microsoft SharePoint Server RCE Vulnerability Lets Low-Privileged Attackers Execute Malicious Code

Microsoft SharePoint Server RCE Vulnerability Lets Low-Privileged Attackers Execute Malicious Code

Microsoft SharePoint is deeply embedded in enterprise collaboration, document management, and internal business workflows. Because SharePoint servers can store sensitive information and connect to other enterprise systems, a vulnerability that enables remote code execution can quickly become more than an application-level security issue.

According to Cybersecurity News, Microsoft disclosed a high-severity vulnerability in SharePoint Server, tracked as CVE-2026-45659, that could allow an authenticated attacker to remotely execute arbitrary code on vulnerable servers. The flaw was disclosed on May 21, 2026, and stems from the deserialization of untrusted data.

What makes the vulnerability particularly concerning is the relatively low privilege required for exploitation. An attacker with as little as Site Member-level permissions can trigger the vulnerability without requiring administrative or elevated privileges.

What Makes CVE-2026-45659 Dangerous?

The vulnerability affects on-premises Microsoft SharePoint deployments and carries a CVSS score of 8.8.

The affected platforms include:

  • Microsoft SharePoint Server Subscription Edition
  • Microsoft SharePoint Server 2019
  • Microsoft SharePoint Enterprise Server 2016

The vulnerability is classified as a deserialization of untrusted data issue.

In simple terms, SharePoint processes serialized data and converts it back into objects that the application can use. If untrusted data is processed without sufficient security controls, an attacker can potentially manipulate that data to cause unintended code execution.

The attack is network-based and has a low attack complexity. Most importantly, the attacker does not need administrator-level access. A minimum of Site Member permissions is sufficient for the attack path described in the report.

How the Attack Works

The attack begins with an attacker obtaining authenticated access to a vulnerable SharePoint environment.

Step 1: Obtain Low-Level SharePoint Access

The attacker first needs an authenticated account with at least Site Member-level permissions.

This could make compromised or abused accounts particularly important from a defensive perspective.

The attacker does not need administrator privileges to proceed.

Step 2: Send Malicious Data to SharePoint

The attacker sends specially crafted data to the vulnerable SharePoint server.

The vulnerability exists in how SharePoint handles the deserialization of untrusted data.

Step 3: Trigger Remote Code Execution

When the vulnerable SharePoint component processes the malicious serialized data, the attacker can cause arbitrary code to execute remotely on the affected server.

This changes the attack from unauthorized application access into server-level compromise.

Step 4: Use the Compromised Server as a Foothold

Once code execution is achieved, the attacker can potentially use the compromised SharePoint server as a starting point for additional malicious activity.

The potential consequences include:

  • Unauthorized access to SharePoint data
  • Malicious code execution
  • Server compromise
  • Further access into connected enterprise infrastructure
  • Potential lateral movement

Because SharePoint is commonly integrated with other enterprise systems, compromise of the server can create risks beyond the original application.

Why the Low Privilege Requirement Matters

One of the most important aspects of CVE-2026-45659 is that exploitation does not require a highly privileged account.

A Site Member-level account is enough.

This creates an important security concern because organizations may have many users with legitimate SharePoint access.

If an attacker obtains one of those accounts, the vulnerability can potentially turn limited application access into remote code execution on the SharePoint server.

This makes identity security and behavioral monitoring particularly important alongside patch management.

SharePoint Becomes the Attack Path

The vulnerability demonstrates how a trusted collaboration platform can become an entry point into a broader enterprise environment.

SharePoint can contain:

  • Business documents
  • Internal communications
  • Project information
  • Sensitive organizational data
  • Access to connected enterprise workflows

A compromise therefore needs to be viewed as an attack-chain problem rather than simply a vulnerable application.

Security teams need to determine not only whether a vulnerable SharePoint server exists, but also whether suspicious activity is occurring around it.

How Seceon Helps Defend Against SharePoint RCE Attacks

For this specific attack, the most relevant Seceon capabilities are aiSecurityScore360, aiSIEM / CGuard, aiXDR-PMax, and aiBAS360.

aiSecurityScore360

Because CVE-2026-45659 affects network-accessible SharePoint infrastructure, identifying exposed and vulnerable assets is an important first step.

Seceon’s aiSecurityScore360 helps organizations gain visibility into their external attack surface and vulnerability exposure.

It can help security teams identify:

  • Internet-facing assets
  • Vulnerability exposure
  • External attack surface risks
  • Security weaknesses that increase an organization’s attackability

This gives security teams greater visibility into whether vulnerable infrastructure is exposed and requires immediate attention.

aiSIEM / CGuard

Once an attacker has authenticated to SharePoint, behavioral correlation becomes critical.

Seceon’s aiSIEM / CGuard helps organizations:

  • Correlate SharePoint authentication events with user activity
  • Identify unusual behavior from Site Member accounts
  • Detect abnormal access patterns
  • Correlate SharePoint activity with network and endpoint events
  • Build a broader timeline around suspicious activity

This is particularly relevant to CVE-2026-45659 because the attack requires authentication but does not require administrative privileges.

A suspicious low-privilege account followed by unusual SharePoint activity and abnormal server behavior can provide important indicators of compromise.

aiXDR-PMax

If exploitation results in code execution on the SharePoint server, monitoring what happens next becomes critical.

Seceon’s aiXDR-PMax helps detect:

  • Suspicious process execution
  • Abnormal activity originating from compromised servers
  • Post-exploitation behavior
  • Privilege escalation attempts
  • Lateral movement following server compromise

This allows security teams to move beyond simply detecting the vulnerable application and focus on the behavior that follows exploitation.

aiBAS360

aiBAS360 can be used to validate whether an organization’s existing security controls can detect and respond to attack paths involving vulnerable enterprise applications.

For a SharePoint environment, organizations can use security validation to test scenarios involving:

  • Initial access through vulnerable services
  • Remote code execution
  • Post-exploitation activity
  • Privilege escalation
  • Lateral movement

This provides security teams with a way to validate detection coverage before a real attacker attempts to exploit the environment.

Patch Management Remains Critical

Detection should not replace remediation.

Microsoft released security updates for the affected SharePoint versions, including:

  • SharePoint Server Subscription Edition: KB5002863
  • SharePoint Server 2019: KB5002870
  • SharePoint Enterprise Server 2016: KB5002868

Organizations should verify that the appropriate security update has been applied and that the affected SharePoint servers are running the patched builds.

Security teams should also review SharePoint permissions and avoid unnecessarily broad Site Member access.

Final Thoughts

CVE-2026-45659 highlights an important shift in enterprise application security.

An attacker does not always need administrator credentials to turn a vulnerable application into a foothold. In this case, relatively low-level authenticated access can potentially be leveraged into remote code execution against the SharePoint server.

For organizations relying on on-premises SharePoint, the defensive strategy should therefore combine exposure management, rapid patching, identity monitoring, behavioral detection, and attack-path validation.

The goal is not simply to know that a SharePoint server is vulnerable. It is to know whether that exposure can be exploited, whether suspicious activity is already occurring, and whether the organization’s security controls can detect the attack before it expands into a broader compromise.

Footer-for-Blogs-3

Categories

Seceon Inc