microsoft
SharePoint Critical RCEs: CVE-2026-45659 + CVE-2026-56164
Technical Advisory & Lab Note: SharePoint Server Deserialization RCEs, Machine-Key Theft, and Post-Exploitation Persistence 1. Executive Summary A coordinated threat-actor campaign is exploiting multiple critical vulnerabilities in Microsoft SharePoint Server on-premises to achieve unauthenticated or low-privilege remote code execution, deploy web shells, steal IIS ASP.