Microsoft patches to fix a security flaw in SharePoint. This issue could let hackers run harmful code without needing special conditions. The flaw, dubbed CVE-2026-45659, has a CVSS score of 8.8. It is rated as a serious issue.
“Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network,” Microsoft said in an advisory released last week.
By infosecbulletin
/ Sunday , June 21 2026
AryStinger has taken control of over 4,000 old D-Link routers to use them as proxies for harmful traffic. The team...
Read More
By infosecbulletin
/ Sunday , June 21 2026
Brazil's government suspects a hacking attack triggered an unauthorized alert sent to cell phones across parts of the country early...
Read More
By infosecbulletin
/ Sunday , June 21 2026
A new open-source cybersecurity tool named CyberSentinel AI v3.0 has come out. It is an important step in self-operated security...
Read More
By infosecbulletin
/ Saturday , June 20 2026
Barracuda gathered industry people in Dhaka on 18 June 2026 for a roundtable talk about cyber resilience. The company shared...
Read More
By infosecbulletin
/ Saturday , June 20 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) asked Fortinet users with FortiGate devices on Thursday to act to protect...
Read More
By infosecbulletin
/ Saturday , June 20 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has asked federal agencies to protect their systems by Sunday from a...
Read More
By infosecbulletin
/ Saturday , June 20 2026
The Texas Parks and Wildlife Department (TPWD) revealed a data leak at its license system provider. This leak exposed private...
Read More
By infosecbulletin
/ Friday , June 19 2026
Cisco has revealed critical security flaws in its Identity Services Engine (ISE). These flaws could let attackers run harmful code...
Read More
By infosecbulletin
/ Thursday , June 18 2026
F5 has shared a security warning about serious flaws in NGINX. These issues could let attackers run any code and...
Read More
By infosecbulletin
/ Wednesday , June 17 2026
A vast cyber spying operation called “FortiBleed” has quietly compromised more than 73,932 different Fortinet firewall URLs in 194 countries....
Read More
Microsoft said that any unauthenticated attacker could cause the vulnerability and it does not need admin or higher permissions.
“In a network-based attack, an authenticated attacker, who has a minimum of Site Member permissions (PR:L), could execute code remotely on the SharePoint Server,” the Windows maker added.
Microsoft thanked a researcher called MEOW for finding and reporting the problem. Updates have been given for these versions –
SharePoint Server Subscription Edition
SharePoint Server 2019
SharePoint Enterprise Server 2016
Last month, Microsoft fixed a security issue with SharePoint Server that allowed fake identities. This flaw, listed as CVE-2026-32201 and rated 6.5 on the CVSS scale, was known to be taken advantage of in real attacks.
The tech giant says CVE-2026-45659 is less likely to be used against users, but it’s still important for users to fix it for better safety. This is especially true because many problems in the platform have often been targeted by attackers in the past.