Microsoft Said "Exploitation Less Likely." Hackers Disagreed.

Microsoft Said "Exploitation Less Likely." Hackers Disagreed.

Microsoft looked at a SharePoint bug that lets any logged-in nobody run code on your server, shrugged, and labeled it "Exploitation Less Likely." Reader, it was exploited. CISA has entered the chat.

A Bug That Doesn't Even Need Your Password

CVE-2026-45659 is a remote code execution flaw in SharePoint Server, born from the classic sin of deserializing untrusted data, and it carries an 8.8 CVSS score. The scary part isn't the number — it's the bar for entry: an attacker only needs basic Site Member permissions, no admin rights, no elevated access, just an ordinary logged-in account to start running code on the server.

Microsoft patched the underlying issue back in May 2026 across SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. CISA added it to the Known Exploited Vulnerabilities catalog on July 1 after confirming attackers were actively using it in the wild, and gave federal agencies until July 4 to patch.

When "Less Likely" Meets "Already Happening"

The gap between Microsoft's risk label and reality is the real story here. "Exploitation Less Likely" is a forecast, not a guarantee, and attackers apparently read the patch notes just as closely as defenders do — sometimes faster.

If your org runs on-prem SharePoint and treats vendor severity ratings as gospel rather than a starting point, this is your reminder that a two-month-old patch sitting unapplied is basically a welcome mat with a CVSS score stapled to it.

Patch first, argue about likelihood ratings later — the ransomware crews certainly aren't waiting for consensus.

Source: The Hacker News