US cyber agency warns over forgotten SharePoint flaw

CISA has added a critical remote code execution flaw in Microsoft SharePoint to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. Organizations are urged to verify their patch levels, as the vulnerability was inadvertently omitted from previous update bulletins.
Why it matters
The oversight in the patch bulletin creates a significant security risk for organizations that rely on automated updates or standard documentation, potentially leaving systems exposed to attackers.
A recently-identified but accidentally unpublicised remote code execution (RCE) flaw in Microsoft SharePoint, tracked as CVE-2026-45659 , has been added to the US Cybersecurity and Infrastructure Security Agency’s (Cisa’s) Known Exploited Vulnerabilities (Kev) catalogue after evidence of active exploitation in the wild was identified.
The article provides technical, factual information regarding cybersecurity risks and vendor updates.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in