SharePoint RCE Added to CISA KEV After Active Exploitation
Severity: HIGH (CVE-2026-45659)
CVSS Score : 8.8

Information
Microsoft SharePoint is a web-based collaboration and document management platform that enables organizations to securely store, manage, and share content and information across teams. It is available as both SharePoint Server for on-premises deployments and SharePoint Online as part of Microsoft 365.
Incident
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerability, tracked as CVE-2026-45659 (CVSS score: 8.8), is a case of remote code execution arising from the deserialization of untrusted data. The issue was addressed by Microsoft in May 2026 for SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016.
Microsoft noted that any authenticated attacker could trigger the vulnerability, and that it does not require admin or other elevated privileges. In a network-based attack, an authenticated attacker with a minimum of Site Member permissions (PR:L) could leverage it to execute code remotely on the SharePoint Server.
Affected Products
Recommendation
The important things is Security systems. We must concern and monitor as usual.
For more information please contact
Email :sales@inetms.co.th
065 149 2822 (Ms.Suphatson )
063 204 4534 (Ms.Atsamaphorn)
065 929 6330 (Ms.Kansinee)
092 257 6902 (Ms.Narusorn)
063 197 7510 (Mr.Yanotai)
065 725 7405 (Ms.Nattharini)
065 725 7405 (Ms.Donraya)
References
Weekly Interesting CVE
| NO. |
CVE Name |
Published Date |
Last Update |
Device/Appplication/OS Target |
Attack Type |
CVSS |
Detail |
Solution |
Reference |
|---|---|---|---|---|---|---|---|---|---|
| 1 |
CVE-2026-53407 |
12/6/2026 |
26/6/2026 |
Zoom Workplace |
Improper Authorization |
8.1 |
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access. |
Upgrade to 7.0.4 for Android |
|
| 2 |
CVE-2026-13028 |
24/6/2026 |
25/6/2026 |
Google Chrome on Android prior to 149.0.7827.197 |
Use After Free |
9.6 |
Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. |
Upgrade to 149.0.7827.197 |
|
| 3 |
CVE-2026-58056 |
28/6/2026 |
29/6/2026 |
RustDesk |
Incorrect Authorization |
7.6 |
RustDesk has an access control vulnerability caused by the way it validates control commands. Instead of checking what the session itself is authorized to do, the system checks based on a feature's "capability" flag. Additionally, when a file-transfer session is opened, the system does not block other unrelated capabilities from being used. |
Update RustDesk to the latest version. |
https://www.vulncheck.com/advisories/rustdesk-filetransfer-session-authorization-scope-bypass |
| 4 |
CVE-2026-54130 |
18/6/2026 |
25/6/2026 |
Microsoft 365 Copilot |
Missing Authentication |
7.5 |
Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
Microsoft has already remediated the vulnerability. |
|
| 5 |
CVE-2026-58058 |
28/6/2026 |
29/6/2026 |
Nmap |
Integer Underflow |
6.9 |
This is a buffer over-read / integer underflow vulnerability in Nmap that occurs when processing malformed IPv6 extension headers. The primary impact is causing Nmap to crash (Denial of Service). It represents a stability-related risk, and patches should be applied once a fix is released. |
Update to version 7.99 or later. |
https://www.vulncheck.com/advisories/nmap-integer-underflow-in-ipv6-extension-header-parsing |
Malware News or Campaign IOC/IOA | EN
|
No |
Campaign Name |
Detection Date |
Attack Type |
Description |
Mitigation/Remediation |
|---|---|---|---|---|---|
| 1 |
New ‘Edgecution’ malware uses browser extension to deploy ransomware |
25/06/2026 |
Malware |
A new malware strain called Edgecution has been discovered by researchers at Zscaler. It uses a malicious Microsoft Edge extension to install a backdoor, allowing attackers to gain unauthorized access to victims' systems. The campaign is believed to have been conducted by the Payouts Kings group, which has been linked to ransomware operations. |
|
Ref: https://www.scworld.com/brief/new-edgecution-malware-uses-browser-extension-to-deploy-ransomware
07 July 2026
Viewed 74 time