Skip to content
Critical SharePoint RCE Vulnerabilities Exploited in the Wild

Critical SharePoint RCE Vulnerabilities Exploited in the Wild

First seen 20 Sep 2026, 13:51 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 21, 2026 at 13:23 UTC
  • CVE-2026-45659 allows RCE via deserialization flaws in SharePoint.
  • CVE-2026-58644 exploits unauthenticated access, enabling persistent code execution.
  • Patching alone is insufficient; organizations must rotate machineKey values.

CVE-2026-45659 and CVE-2026-58644 are critical remote code execution (RCE) vulnerabilities affecting Microsoft SharePoint Server. CVE-2026-45659, published on May 22, 2026, allows authenticated users to exploit deserialization flaws for RCE under the IIS application pool identity. CVE-2026-58644, discovered in July 2026, enables unauthenticated attackers to execute arbitrary code via a multi-stage exploit chain known as ToolShell. The exploitation of these vulnerabilities has been confirmed in the wild, with CVE-2026-58644 being actively exploited despite a patch released on July 14, 2026. Attackers can leverage stolen machineKey material to forge valid payloads, bypassing authentication checks. Organizations are urged to apply the latest security updates and rotate machineKey values to mitigate risks. The ongoing exploitation of these vulnerabilities highlights a significant shift in targeting enterprise infrastructure. Microsoft SharePoint is increasingly viewed as a primary target for attackers, indicating a need for heightened security measures.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-05-22
CVE-2026-45659 published
Critical deserialization flaw in SharePoint allowing RCE under IIS identity.
Socprime
2026-07-14
CVE-2026-58644 patch released
Microsoft released a patch for the unauthenticated RCE vulnerability in SharePoint.
Forkast.News
2026-07-14
CVE-2026-55040 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-16
CVE-2026-58644 added to CISA KEV
CISA confirmed active exploitation of the vulnerability shortly after patch release.
Forkast.News
2026-09-20
Ongoing exploitation confirmed
Exploitation of CVE-2026-58644 continues despite patch, indicating persistent threat.
Forkast.News

More articles in this cluster (3)

Following this threat?

Track CVE-2026-45659 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed