A serious security flaw in Microsoft SharePoint Server is being actively exploited by attackers, and the US government's cyber security agency has confirmed real-world attacks are underway.
- What it is: A remote code execution vulnerability (CVE-2026-45659) in on-premises SharePoint Server that lets an attacker with only basic site access run malicious code on the server.
- Who is affected: Businesses running SharePoint Server 2016, 2019, or Subscription Edition on their own infrastructure. This does not affect SharePoint Online in Microsoft 365.
- What the risk is: An attacker who exploits this flaw can gain full control of the SharePoint server, exposing files, credentials, and any connected systems.
- What to do: Microsoft released a patch for this issue in May 2026. If your SharePoint Server has not been updated since then, we recommend patching it immediately.
- Also worth noting: A separate authentication bypass in the SimpleHelp remote support tool is also under active attack and being used to deliver information-stealing malware, so businesses using SimpleHelp should confirm they are on the latest version.
We recommend confirming patch status on any on-premises SharePoint or remote-support software this week, and getting in touch if you are unsure whether your systems are affected.