Microsoft looked at a remote code execution hole in SharePoint back in May, shrugged, and told customers exploitation was "less likely." Six weeks later, CISA slapped it on the federal must-patch-immediately list. Reader, it was not less likely.
The Bug Nobody Needed This Summer
CVE-2026-45659 is a deserialization flaw in SharePoint Server, and it's nasty in a very specific way: any authenticated attacker with nothing more than basic Site Member permissions can trigger remote code execution. No admin rights required, no elevated access, just a foothold and some patience. It carries a CVSS score of 8.8.
Microsoft patched it in May across SharePoint Server Subscription Edition, SharePoint 2019, and SharePoint Enterprise Server 2016. On July 1, CISA added it to the Known Exploited Vulnerabilities catalog and gave federal agencies a three-day patch window under binding directive BOD 26-04, which is government-speak for "drop what you're doing."
When "Unlikely" Turns Out to Mean "Untested"
The gap between "patched in May" and "actively exploited by July" is the part worth sitting with. Plenty of organizations read Microsoft's original severity guidance, filed the patch under "get to it eventually," and are now finding out the hard way that vendor exploitability predictions are educated guesses, not guarantees.
This lands the same week CitrixBleed 2 exploitation matured into actual DragonForce ransomware deployments, which tells you where the ransomware crews' attention is right now: internet-facing enterprise software that took its sweet time getting patched.
If your org runs on-prem SharePoint, this is your reminder that "less likely" is not a patch management strategy. Go check your version number.
Source: BleepingComputer