CISA announces that it adds a high-severity Microsoft SharePoint Server remote code execution vulnerability, CVE-2026-45659, to its Known Exploited Vulnerabilities (KEV) catalog. Multiple outlets report that CISA’s decision is based on evidence indicating active exploitation of the flaw. The vulnerability is described as an RCE condition involving the deserialization of untrusted data. Sources cite a CVSS score of 8.8 and note that Microsoft previously patched the issue in May. Bleeping Computer and SecurityWeek both state that threat actors are already exploiting the vulnerability in the wild, prompting the KEV update. The Register adds that exploitation requires access to a SharePoint account, and characterizes Microsoft’s earlier position as suggesting exploitation is less likely, while CISA’s KEV listing reflects its view that exploitation is occurring. Overall, the reporting aligns on the core points: the specific CVE, its RCE impact, its high severity rating, the May patch, and CISA’s determination that it is being actively exploited.