Forkast.News Critical SharePoint RCE Vulnerabilities Exploited in the Wild
Article Content
- •CVE-2026-45659 allows RCE via deserialization flaws in SharePoint.
- •CVE-2026-58644 exploits unauthenticated access, enabling persistent code execution.
- •Patching alone is insufficient; organizations must rotate machineKey values.
CVE-2026-45659 and CVE-2026-58644 are critical remote code execution (RCE) vulnerabilities affecting Microsoft SharePoint Server. CVE-2026-45659, published on May 22, 2026, allows authenticated users to exploit deserialization flaws for RCE under the IIS application pool identity. CVE-2026-58644, discovered in July 2026, enables unauthenticated attackers to execute arbitrary code via a multi-stage exploit chain known as ToolShell. The exploitation of these vulnerabilities has been confirmed in the wild, with CVE-2026-58644 being actively exploited despite a patch released on July 14, 2026. Attackers can leverage stolen machineKey material to forge valid payloads, bypassing authentication checks. Organizations are urged to apply the latest security updates and rotate machineKey values to mitigate risks. The ongoing exploitation of these vulnerabilities highlights a significant shift in targeting enterprise infrastructure. Microsoft SharePoint is increasingly viewed as a primary target for attackers, indicating a need for heightened security measures.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-45659 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Red Heron Exploits Gitea RCE Flaw in Multinational Campaign A Chinese-speaking threat actor, tracked as Red Heron, exploited the CVE-2026-60004 remote code execution vulnerability in Gitea, compromising 1,386 instances across seven countries. The campaign involved source-code theft, credential collection, and lateral movement, affecting organizations in Canada, Argentina…