SharePoint RCE Added to CISA KEV After Active Exploitation

SharePoint RCE Added to CISA KEV After Active Exploitation

Severity: HIGH (CVE-2026-45659)

CVSS Score : 8.8

Information

  Microsoft SharePoint is a web-based collaboration and document management platform that enables organizations to securely store, manage, and share content and information across teams. It is available as both SharePoint Server for on-premises deployments and SharePoint Online as part of Microsoft 365.

Incident

  The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a high-severity flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

  The vulnerability, tracked as CVE-2026-45659 (CVSS score: 8.8), is a case of remote code execution arising from the deserialization of untrusted data. The issue was addressed by Microsoft in May 2026 for SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016.

  Microsoft noted that any authenticated attacker could trigger the vulnerability, and that it does not require admin or other elevated privileges. In a network-based attack, an authenticated attacker with a minimum of Site Member permissions (PR:L) could leverage it to execute code remotely on the SharePoint Server.

Affected Products

  • SharePoint Server Subscription Edition
  • SharePoint Server 2019
  • SharePoint Enterprise Server 2016

Recommendation

  • Apply the latest Microsoft security updates.
  • Review SharePoint accounts for unnecessary or stale low-privilege users.
  • Review and enforce the principle of least privilege

The important things is Security systems. We must concern and monitor as usual.
For more information please contact
Email :sales@inetms.co.th
065 149 2822 (Ms.Suphatson )
063 204 4534 (Ms.Atsamaphorn)
065 929 6330 (Ms.Kansinee)
092 257 6902 (Ms.Narusorn)
063 197 7510 (Mr.Yanotai)
065 725 7405 (Ms.Nattharini)
065 725 7405 (Ms.Donraya)

References

Weekly Interesting CVE

NO.

CVE Name

Published Date

Last Update

Device/Appplication/OS Target

Attack Type

CVSS
Severity Rating

Detail

Solution

Reference

1

CVE-2026-53407

12/6/2026

26/6/2026

Zoom Workplace
before version 7.0.4 for Android and
before 7.0.3 for iOS

Improper Authorization

8.1

Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.

Upgrade to 7.0.4 for Android
and
Upgrade to 7.0.3 for IOS

https://nvd.nist.gov/vuln/detail/CVE-2026-53407

2

CVE-2026-13028

24/6/2026

25/6/2026

Google Chrome on Android prior to 149.0.7827.197

Use After Free

9.6

Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

Upgrade to 149.0.7827.197

https://nvd.nist.gov/vuln/detail/CVE-2026-13028

3

CVE-2026-58056

28/6/2026

29/6/2026

RustDesk

Incorrect Authorization

7.6

RustDesk has an access control vulnerability caused by the way it validates control commands. Instead of checking what the session itself is authorized to do, the system checks based on a feature's "capability" flag. Additionally, when a file-transfer session is opened, the system does not block other unrelated capabilities from being used.
As a result, a peer who only requested file-transfer permission can covertly control the other party's keyboard and mouse, as well as secretly view their screen. This is classified as a privilege escalation vulnerability and should be fixed as soon as possible.

Update RustDesk to the latest version.

https://www.vulncheck.com/advisories/rustdesk-filetransfer-session-authorization-scope-bypass

 4

CVE-2026-54130

18/6/2026

25/6/2026

Microsoft 365 Copilot

Missing Authentication

7.5

Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Microsoft has already remediated the vulnerability.

https://nvd.nist.gov/vuln/detail/CVE-2026-54130

5

CVE-2026-58058

28/6/2026

29/6/2026

Nmap

Integer Underflow

6.9

This is a buffer over-read / integer underflow vulnerability in Nmap that occurs when processing malformed IPv6 extension headers. The primary impact is causing Nmap to crash (Denial of Service). It represents a stability-related risk, and patches should be applied once a fix is released.

Update to version 7.99 or later.

https://www.vulncheck.com/advisories/nmap-integer-underflow-in-ipv6-extension-header-parsing

Malware News or Campaign IOC/IOA | EN

No

Campaign Name

Detection Date

Attack

Type

 

Description

 

Mitigation/Remediation

1

New ‘Edgecution’ malware uses browser extension to deploy ransomware​

25/06/2026​

Malware

A new malware strain called Edgecution has been discovered by researchers at Zscaler. It uses a malicious Microsoft Edge extension to install a backdoor, allowing attackers to gain unauthorized access to victims' systems. The campaign is believed to have been conducted by the Payouts Kings group, which has been linked to ransomware operations.​

  • Remove browser extensions that are no longer in use or originate from unknown sources.​
  • Install browser extensions only from trusted developers.​
  • Keep your browser and operating system up to date with the latest versions.​
  • Conduct security awareness training for employees to help them recognize and prevent cyber threats.​

Ref: https://www.scworld.com/brief/new-edgecution-malware-uses-browser-extension-to-deploy-ransomware

07 July 2026

Viewed 74 time

Engine by shopup.com