Microsoft patches to fix a security flaw in SharePoint. This issue could let hackers run harmful code without needing special conditions. The flaw, dubbed CVE-2026-45659, has a CVSS score of 8.8. It is rated as a serious issue.
“Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network,” Microsoft said in an advisory released last week.
By infosecbulletin
/ Wednesday , August 26 2026
A cyberattack using open-source AI tools almost ran on its own. It affected government systems in Asia, compromised into 85...
Read More
By infosecbulletin
/ Tuesday , August 25 2026
Threat actors have already compromised more than 270 Zimbra instances in attacks that let them run code remotely. These attacks...
Read More
By infosecbulletin
/ Tuesday , August 25 2026
Singapore has picked four data-centre plans for a total of 200MW of power in its second Data Centre Call for...
Read More
By infosecbulletin
/ Tuesday , August 25 2026
Bank customers looking for a login page can now fall into a trap before getting a strange email or text....
Read More
By infosecbulletin
/ Monday , August 24 2026
A mysterious AI model dubbed "Ox Alpha" has surfaced online and created noise within the developer community after releasing on...
Read More
By infosecbulletin
/ Monday , August 24 2026
A group of hackers named “Madarax” claims they have stolen and are offering to sell the personal information of about...
Read More
By infosecbulletin
/ Monday , August 24 2026
A new hacking technique has been demonstrated to steal data from Elon Musk's Grok AI. It uses a simple trick...
Read More
By infosecbulletin
/ Sunday , August 23 2026
More than 9,300 AWS access keys that were made public from August 2022 to August 2026 are still active, says...
Read More
By infosecbulletin
/ Sunday , August 23 2026
US Bank is looking into LockBit's claims about a breach and stolen data. The ransomware group says they will share...
Read More
By infosecbulletin
/ Friday , August 21 2026
Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
Microsoft said that any unauthenticated attacker could cause the vulnerability and it does not need admin or higher permissions.
“In a network-based attack, an authenticated attacker, who has a minimum of Site Member permissions (PR:L), could execute code remotely on the SharePoint Server,” the Windows maker added.
Microsoft thanked a researcher called MEOW for finding and reporting the problem. Updates have been given for these versions –
SharePoint Server Subscription Edition
SharePoint Server 2019
SharePoint Enterprise Server 2016
Last month, Microsoft fixed a security issue with SharePoint Server that allowed fake identities. This flaw, listed as CVE-2026-32201 and rated 6.5 on the CVSS scale, was known to be taken advantage of in real attacks.
The tech giant says CVE-2026-45659 is less likely to be used against users, but it’s still important for users to fix it for better safety. This is especially true because many problems in the platform have often been targeted by attackers in the past.