Summary
Microsoft SharePoint Server’s deserialization handling can process attacker-controlled data. An authenticated attacker with the required SharePoint permissions can send a crafted network request that reaches the vulnerable server-side code path and trigger code execution without user interaction. Successful exploitation can compromise the SharePoint host and expose or alter stored content.
Why Planned Fix?
4/6Exploitation Details
Execute arbitrary code remotely on the SharePoint server
RCE (Remote Code Execution)Affected Software
| Product | Affected Versions |
|---|---|
| Microsoft SharePoint Enterprise Server 2016 | prior to 16.0.5552.1002 |
| Microsoft SharePoint Server 2019 | prior to 16.0.10417.20128 |
| Microsoft SharePoint Server Subscription Edition | prior to 16.0.19725.20280 |
On-premises collaboration and document management platform used for intranets, team sites, portals, and shared business content.
Affected ComponentServer-side deserialization logic in SharePoint request processing.
Server-side deserialization logic in SharePoint request processing.
Not available
Not available
Install the May 12, 2026 SharePoint security updates for your release line: KB5002868 for SharePoint Server 2016 (build 16.0.5552.1002), KB5002870 for SharePoint Server 2019 (build 16.0.10417.20128), or KB5002863 for SharePoint Server Subscription Edition (build 16.0.19725.20280).
Install the May 12, 2026 SharePoint security updates for your release line: KB5002868 for SharePoint Server 2016 (build 16.0.5552.1002), KB5002870 for SharePoint Server 2019 (build 16.0.10417.20128), or KB5002863 for SharePoint Server Subscription Edition (build 16.0.19725.20280).
Probability of exploitation in the next 30 days
Worse than 66% of all CVEs
No known threat actors
No detection rules available
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Sources
| Source | Article |
|---|---|
| msrc.microsoft.com | Security Update Guide - CVE-2026-45659 |
| nvd.nist.gov | CVE-2026-45659 Detail |
| cert.ssi.gouv.fr | CERT-FR Advisory CERTFR-2026-AVI-0634 |
| www.helpnetsecurity.com | High-severity SharePoint RCE bug patched by Microsoft |
| support.microsoft.com | May 2026 updates for Microsoft Office |
| support.microsoft.com | SharePoint Server Subscription Edition: May 12, 2026 (KB5002863) |
| support.microsoft.com | SharePoint Server 2019: 12 de mayo de 2026 (KB5002870) |
| support.microsoft.com | SharePoint Server 2016: May 12, 2026 (KB5002868) |
Priority History
Initial analysis