Overview
What is CVE-2026-45659?
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
CISA lists CVE-2026-45659 in its Known Exploited Vulnerabilities catalog, which means exploitation has been observed. The entry applies to Microsoft SharePoint Server.
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.