A serious security flaw in Microsoft SharePoint Server is being actively exploited by attackers right now, and the US Cybersecurity and Infrastructure Security Agency (CISA) has added it to its list of vulnerabilities under attack.
- What it is: A remote code execution vulnerability (CVE-2026-45659) in SharePoint Server that lets an attacker run malicious code on an affected system without needing valid credentials.
- Who is affected: Organisations running on-premises or hybrid SharePoint Server. Fully cloud-based SharePoint Online through Microsoft 365 is not affected by this particular flaw.
- The risk: Successful exploitation can give an attacker full control of the server, including access to stored documents and the ability to move further into your network.
- What to do: Apply Microsoft's latest SharePoint Server security update as soon as possible, and confirm with your IT provider that patching has been completed.
If you run SharePoint Server on-premises and have not confirmed this patch is installed, we recommend treating it as urgent. Businesses using SharePoint Online only are not exposed to this specific issue.