No — CVE-2026-45659 (CVSS 8.8) is being actively exploited by ransomware gangs and has been in the CISA KEV catalog since July 2, 2026. The flaw is a remote code execution (RCE) via deserialization of untrusted data in Microsoft SharePoint Server — an authenticated user with only the Site Member role (no admin rights) can execute code on the server. A patch has existed since May 2026, yet exploitation persists regardless — organizations that have not patched SharePoint are a real target. In the context of NIS2 art. 21(2), this is a concrete case of failed vulnerability management and patch management.
Key facts
- CVE-2026-45659 (CVSS 8.8) was added to the CISA Known Exploited Vulnerabilities catalog on July 2, 2026 after confirmation of active exploitation — the flaw was exploited as early as July, even though the patch existed since May.
- Root cause: RCE via deserialization of untrusted data in SharePoint Server — an authenticated attacker with the Site Member role (without admin privileges) can execute code remotely.
- Impact: full takeover of the SharePoint server, and for ransomware gangs this is a gateway to escalation, file encryption and extortion.
- Patches were released by Microsoft in May 2026 for SharePoint Server Subscription Edition and SharePoint Server 2019 — organizations that have not applied the updates are exposed.
- CISA linked CVE-2026-45659 to a chain of related SharePoint flaws (including CVE-2026-32201, CVE-2026-56164, CVE-2026-58644), indicating deliberate, complex chain attacks rather than isolated exploits.
- Under NIS2 art. 21(2)(e) (vulnerability management) and art. 21(2)(c) (business continuity) — an unpatched SharePoint is a breach of the risk management obligation.
Decision table: what we know → what it means for B2B / manufacturing → what to do
| Area | What we know | What it means for a B2B / manufacturing firm | 30-day action | 90-day action |
|---|---|---|---|---|
| Patch management | Microsoft patch available since May 2026; CVE in KEV since 02.07.2026 | An unpatched SharePoint is an open RCE gateway for ransomware | Confirm SharePoint version and apply the cumulative update immediately | Automate patch management (class A); "KEV patch in 14 days" KPI |
| SharePoint exposure | SharePoint often exposed to employees/partners via internet or VPN | The document server is the core of collaboration — ransomware halts the business | Restrict SharePoint access to necessary roles; enforce MFA; audit Site Member rights | Segmentation, reverse proxy, monitoring of farm access |
| Site Member rights | Attacker needs only the Site Member role (no admin) | Over-broad roles lower the barrier for the attacker | Review and minimize permissions; remove unused accounts | Periodic permission audits; zero-trust access model to SharePoint |
| Deserialization / hardening | CISA recommends SharePoint hardening (deserialization protection, IIS machine keys) | Deserialization is a recurring vector — worth closing at the source | Apply CISA SharePoint hardening recommendations; rotate IIS keys | Monitor deserialization events; EDR rules on the farm |
| Incident response | CVE actively used by ransomware; exploit works despite the patch | You must know whether an incident already occurred before patching | Enable SharePoint logs to SIEM; retrospect events before the patch | IR playbook for SharePoint; backup restore testing |
| NIS2 / KSC compliance | Art. 21(2)(e) vulnerability management; art. 23 incident reporting | Neglecting a KEV-listed flaw is a basis for liability over missing patch management | Entry in the risk register; board report on KEV status | CHORS KSC/NIS2 Compliance Program with continuous readiness |
Perspective of Marcin Białczyk (CHORS.NET)
SharePoint is for many B2B and manufacturing firms "hidden critical infrastructure": it runs in a farm, serves documents, intranet and approval workflows, yet nobody treats it as a front-line system. The fact that CVE-2026-45659 requires only the Site Member role is operationally decisive — this is not about a full-privilege administrator, but an ordinary project user. That lowers the entry barrier to a level where phishing a single employee account can turn into RCE on the document server. From my operational experience, SharePoint is precisely the system that gets skipped in routine patch management because "it's just intranet" — a costly mistake once ransomware shows up.
At CHORS.NET we see CVE-2026-45659 as a model case for CHORS NIS2/KSC Start or CHORS KSC/NIS2 Compliance Program — not because we patch SharePoint for the client (their team or vendor does), but because the client needs a fast view: is the SharePoint version current, who holds the Site Member role, do logs reach the SIEM, are IIS keys safe. This is an operational audit, not a marketing "security audit". CISA explicitly links this flaw to a chain of related CVEs — patching just one of them is not enough; the whole SharePoint farm must be hardened.
Frequently asked questions
1. Does CVE-2026-45659 require administrator privileges to exploit?
No — an attacker needs only an account with the Site Member role (a site member), without administrator rights. This makes the flaw especially dangerous because the entry barrier is low.
2. Does the patch really exist and does the exploit work despite it?
Yes, Microsoft released updates in May 2026 for SharePoint Server Subscription Edition and SharePoint Server 2019. Yet CISA confirmed active exploitation as early as July — meaning many environments did not apply the patches.
3. What can I do if I cannot patch SharePoint immediately?
Apply temporary mitigations: restrict access to the farm, enforce MFA for all roles, minimize Site Member privileges, and apply CISA SharePoint hardening recommendations with IIS key rotation. This does not waive the obligation to patch at the earliest possible window.
4. Do I have to report this incident to CSIRT NASK / KSC?
The mere existence of the CVE does not require reporting — what requires reporting is the actual incident (confirmed exploit, RCE, encryption). If your SharePoint has been compromised, it is a security incident subject to severity assessment (NIS2 art. 23, KSC art. 11).
How CHORS.NET helps
CHORS.NET supports the technical-operational side: passive exposure assessment, configuration verification, evidence packs and NIS2/KSC readiness support. See: Services, About CHORS.NET and Contact.
Boundaries and assumptions
- We are not a SOC 24/7 and we do not guarantee detection of every incident.
- We do not certify NIS2/KSC compliance and we do not issue an independent legal opinion.
- Results reflect the state at the time of the article (2026-08-13).
- For legal interpretation of NIS2/KSC, CHORS works with law firms.
- This material is informational and technical; it is not legal advice and not a guarantee of security.
- We do not use claims of "full compliance", a "compliance certificate" or "guarantee of detection".
Sources
- BleepingComputer — CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
- CISA Known Exploited Vulnerabilities Catalog
- CISA — Cybersecurity Alerts (SharePoint)
- The Hacker News — SharePoint RCE CVE-2026-45659 added to CISA KEV after active exploitation
- NVD — CVE-2026-45659 entry (nvd.nist.gov)
- CISA — Known Exploited Vulnerabilities Catalog (official)
- NIS2 Directive (EU 2022/2555), art. 21(2) and art. 23
Footer
Author: Marcin Białczyk, Founder & Cybersecurity Operator at CHORS.NET Updated: 2026-08-13