[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fNezBwyIwVmu-IR3g5UaM0VLeRQS_hvc1laZFQo3skmk":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"1e10719e-3ff8-4c8b-a7a7-85fc248424a4","active-exploitation-of-microsoft-sharepoint-deserialization-flaw-highlights-patching-urgency","71af385a-6c45-4f76-b6e1-abdd9f8a0200","Active Exploitation of Microsoft SharePoint Deserialization Flaw Highlights Patching Urgency","CVE-2026-45659, a deserialization vulnerability in Microsoft SharePoint Server, is being actively exploited in the wild, prompting CISA to add it to its Known Exploited Vulnerabilities (KEV) Catalog. Deserialization flaws are particularly dangerous because they can allow attackers to execute arbitrary code on affected systems, potentially leading to full server compromise. Federal agencies are now mandated under BOD 26-04 to remediate this vulnerability on publicly exposed assets, but the risk extends to all organizations running unpatched SharePoint environments. This incident underscores that delayed patching of internet-facing systems dramatically increases the attack surface and the likelihood of successful exploitation.","**Immediate Actions:**\n- Apply the latest Microsoft SharePoint Server security patches immediately, prioritizing any internet-facing or publicly exposed instances.\n- Run an authenticated vulnerability scan across all SharePoint deployments to confirm patch status and identify any missed instances.\n\n**Long-term Improvements:**\n- Establish a risk-based vulnerability management program that mandates emergency patching SLAs (e.g., 24–72 hours) for actively exploited CVEs listed in CISA's KEV Catalog.\n- Maintain a continuously updated asset inventory to ensure no SharePoint or other critical servers are overlooked during patch cycles.\n- Restrict public exposure of SharePoint instances using network segmentation and Web Application Firewalls (WAFs) to limit the attack surface.\n\n**Detection Measures:**\n- Enable detailed logging on SharePoint servers and ship logs to a SIEM to detect anomalous deserialization activity or unexpected code execution attempts.\n- Subscribe to CISA KEV Catalog alerts and threat intelligence feeds to receive real-time notification of newly exploited vulnerabilities relevant to your environment.",[12,13,14,15,16,17,18,19],"CIS Control 7: Continuous Vulnerability Management","CIS Control 2: Inventory and Control of Software Assets","NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management Planning","NIST SI-2: Flaw Remediation","NIST RA-5: Vulnerability Monitoring and Scanning","CISA Binding Operational Directive (BOD) 22-01: Known Exploited Vulnerabilities Catalog","NIST CSF 2.0: RS.AN (Incident Analysis)","ISO\u002FIEC 27001:2022 A.8.8: Management of Technical Vulnerabilities","published","2026-07-01T22:22:00.557505+00:00","2026-07-01T22:22:00.271+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Falerts\u002F2026\u002F07\u002F01\u002Fcisa-adds-one-known-exploited-vulnerability-catalog","cisa-adds-one-known-exploited-vulnerability-to-catalog-2bd85f","CISA Adds One Known Exploited Vulnerability to Catalog",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":35,"name":36,"slug":37,"description":38,"color":39},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]