Microsoft releases security updates to address CVE-2026-45659, a high-severity remote code execution (RCE) vulnerability affecting Microsoft SharePoint. Multiple reports say the issue is tied to SharePoint deserializing untrusted data. According to the descriptions, an attacker with authentication can exploit the weakness to execute code remotely on a vulnerable SharePoint Server installation, and the attacks do not require user interaction.

The vulnerability applies to several SharePoint Server products, including SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. One outlet also reports a CVSS score of 8.8 and characterizes the flaw as having low attack complexity. Across sources, Microsoft’s response is consistent: it provides patched versions to mitigate the RCE risk.

The reported scope and exploitation model are the central points: authenticated attackers can trigger remote code execution through crafted inputs that leverage the unsafe deserialization behavior, and Microsoft’s updates are intended to prevent exploitation on affected systems.