A remote code execution flaw in Microsoft SharePoint, tracked as CVE-2026-45659, was added to CISA’s Known Exploited Vulnerabilities catalogue earlier this month after confirmed active exploitation by the threat group Storm-2603. Microsoft issued a patch back in May, but the vulnerability is still being used against organisations that haven’t applied it — and the attack itself is straightforward: an attacker with only basic “Site Member” permissions can trigger it, with no need for elevated privileges or deep technical sophistication.
The good news first: if your business runs SharePoint Online as part of Microsoft 365, you’re not affected. Microsoft patches and operates that infrastructure directly, so there’s nothing for you to do. The flaw only hits on-premise deployments — SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016 — the kind of setup more common among businesses with legacy systems, specific compliance requirements, or an IT estate that’s grown organically rather than been rebuilt cloud-first.
Why this one keeps resurfacing
CVE-2026-45659 isn’t new — it was patched out-of-band in May — but it keeps making headlines because patching an on-premise SharePoint server isn’t always as simple as clicking “update.” These are often systems that host sensitive internal documents, HR records, or client files, run by IT teams or MSPs who need to schedule downtime, test compatibility with other tools, and coordinate the change. That gap between “patch available” and “patch applied” is exactly where attackers operate, and CVE-2026-45659 has now had months for that gap to be exploited by anyone still behind.
CISA’s decision to add the flaw to its Known Exploited Vulnerabilities catalogue isn’t a routine bulletin — that list is reserved for vulnerabilities with confirmed, real-world exploitation, not theoretical risk. It’s a signal that this isn’t a “patch it eventually” item on a long backlog; it’s one that a specific, named threat group is actively using against real organisations right now, which is a meaningfully different level of urgency than most of the security advisories that cross an IT team’s desk in a given month.
If you’re not sure whether this applies to you
The honest first step is finding out what you’re actually running. A surprising number of SMEs inherited an on-premise SharePoint deployment from a previous IT provider, a merger, or a system nobody’s touched since it was set up years ago, and don’t have a clear, current picture of its patch status. If nobody in your business can confidently answer “are we on SharePoint Online or an on-premise server, and is it patched,” that’s the question to resolve this week, not the patch itself. Once you know, applying Microsoft’s May update — or confirming your MSP already has — closes the door. CoolCoding can help audit exactly which systems you’re running and whether they’re exposed, if that picture isn’t clear internally.
The wider habit worth building
This pattern — a patch exists, but the gap between release and application gets exploited — repeats constantly in cybersecurity, and it’s rarely about the specific software. It’s about whether a business has a routine for tracking what it runs and keeping it updated. If your current approach to patching is “we’ll get to it when something breaks,” CVE-2026-45659 is a useful prompt to build a lighter-touch version: a monthly check-in with whoever manages your IT, asking specifically what’s outstanding and why.
The takeaway
If you know for certain you’re on SharePoint Online, this one doesn’t touch you. If you’re running an on-premise SharePoint server, or you’re not sure which you have, treat that uncertainty as the actual priority — confirm your setup, apply May’s patch if it hasn’t already gone on, and use this as the nudge to get a proper handle on what your business exposes and how current its patching really is.