Summary
A working proof-of-concept exploit for a two-vulnerability remote code execution chain affecting Microsoft SharePoint Server was published on August 25, 2026, elevating the exploitation risk for the estimated 200-plus unpatched on-premises SharePoint servers that Shadowserver Foundation continues to track. The chain combines CVE-2026-45659, a high-severity deserialization vulnerability requiring low site-level privileges that CISA confirmed was already being exploited in ransomware attacks on August 10, with CVE-2026-45657, a separate server-side request forgery flaw. An attacker who chains the two vulnerabilities can achieve unauthenticated remote code execution on a target SharePoint server. Microsoft patched both vulnerabilities in May 2026. The CISA KEV entry for CVE-2026-45659 was updated on August 10 to reflect confirmed ransomware exploitation. The publication of a working PoC for the combined chain converts a known-exploited vulnerability into one where the exploitation barrier has dropped to near zero for any attacker with basic technical competence. Security researchers who published the PoC confirmed they responsibly disclosed the chain to Microsoft before publication and coordinated timing with the patch availability.
| Date | Event |
|---|---|
| May 2026 | Microsoft patches CVE-2026-45659 and CVE-2026-45657 in SharePoint Enterprise Server 2016, Server 2019, and Subscription Edition |
| Jul 1, 2026 | CISA adds CVE-2026-45659 to KEV catalog |
| Aug 10, 2026 | CISA updates KEV entry: CVE-2026-45659 confirmed exploited in ransomware attacks — see TTO-2026-0812-001 |
| Aug 25, 2026 | Working PoC published for two-CVE RCE chain combining CVE-2026-45659 and CVE-2026-45657 |
| Aug 26, 2026 | 200+ unpatched SharePoint servers remain internet-exposed per Shadowserver Foundation |
Domain Intelligence
| Domain | Score | DKIM | SPF | DMARC | Status |
|---|---|---|---|---|---|
| sharepoint.com | 62.48 | ✓ | ✓ | ✓ | Live |
Context
sharepoint.com scores 62.48 at the time of this bulletin — down from 71.35 when The Trust Observatory first documented CVE-2026-45659 exploitation in TTO-2026-0812-001 fourteen days ago. That is not a rounding difference. It is a 9-point drop in the domain's trust profile over two weeks, captured by WarmBadge's live signal aggregation as new intelligence updated the domain's reputation signals in real time. A domain's WarmBadge score is not a fixed rating assigned at a point in time. It reflects the current state of every signal the engine tracks, updated continuously. What a domain scored two weeks ago is historical record. What it scores today is the live read. The gap between those two numbers is information.
The two-CVE chain publication materially changes the operational risk calculus for organizations still running unpatched SharePoint Server. CVE-2026-45659 was already confirmed in ransomware attacks before a public PoC existed. A weaponized PoC removes the technical barrier that previously limited exploitation to threat actors capable of independently developing working exploits. The pool of actors capable of exploiting a vulnerability with a published PoC is categorically larger than the pool capable of weaponizing a vulnerability without one. Any organization running unpatched SharePoint Server with internet exposure should treat that system as a priority incident response case rather than a standard patch backlog item.
The Trust Observatory · thetrustobservatory.com · August 26, 2026