Have any questions? +1 646.844.5712 (US)

  • Facebook
  • LinkedIn
  • Twitter
HiTech ServiceHiTech Service
  • Home
  • About
  • Services
    • Software Development
    • Customer Support
    • Quality Assurance
    • Managed Services
    • Compliance Audit
    • GDPR Compliance
    • Competency Center
    • Emergency IT Support
    • Software as medical device
    • Local AI Agent Development
  • Projects
  • GDPR
  • Articles
  • Case Studies
  • Contact
Menu
  • Home
  • About
  • Services
    • Software Development
    • Customer Support
    • Quality Assurance
    • Managed Services
    • Compliance Audit
    • GDPR Compliance
    • Competency Center
    • Emergency IT Support
    • Software as medical device
    • Local AI Agent Development
  • Projects
  • GDPR
  • Articles
  • Case Studies
  • Contact
A cracked circuit-board shield partially covered by a glowing gold patch, with a calendar in the background symbolizing time passing since the patch was released

Microsoft Patched This SharePoint Bug in May. CISA Gave Agencies 3 Days to Fix It in July. Here’s the Gap That Matters.

By Dmitriy

On July 1, 2026, CISA added a Microsoft SharePoint Server vulnerability to its Known Exploited Vulnerabilities catalog and told federal agencies to fix it by July 4 — a three-day window, about as urgent as the agency’s directive gets. The vulnerability itself, tracked as CVE-2026-45659, wasn’t new. Microsoft had already shipped a fix for it in an out-of-band security update back in late May.

That two-month gap between “patch exists” and “attackers are actively using this against unpatched systems” is the actual story here. The vulnerability is a detail. The gap is the pattern that keeps recurring across nearly every KEV entry, and it’s worth understanding why it keeps happening even at organizations that, on paper, have a patch management process.

What the Bug Actually Does

CVE-2026-45659 is a deserialization-of-untrusted-data flaw in SharePoint Server, carrying a CVSS score of 8.8. Microsoft’s own advisory describes the exploitation path: an attacker who’s already authenticated to SharePoint — needing nothing more than baseline Site Member permissions, not an administrator account — can trigger remote code execution over the network, with no user interaction required on the victim’s end. That’s a meaningfully low bar. It doesn’t require phishing someone into clicking a link or tricking an admin into running a malicious file; a low-privilege account that’s already inside the system is enough to escalate to full code execution.

CISA confirmed active exploitation when it added the CVE to the KEV catalog but hasn’t published details of the observed attacks — standard practice, since disclosing exploitation specifics can hand attackers a roadmap while investigations are ongoing.

Why “Patched in May, Exploited in July” Is the Normal Case, Not the Exception

A timeline connecting a shield-checkmark icon representing a patch release to a warning-triangle icon representing active exploitation, with an empty gap between them

It’s tempting to read a KEV addition as “a new threat just emerged.” Far more often, what actually happened is that a patch has existed for weeks or months, and the newsworthy event is attackers finally getting around to weaponizing it against the population of systems that never applied it. SharePoint Server, in particular, tends to run in enterprise environments where patching means real downtime, change-management approval, and testing against custom configurations and third-party integrations — the opposite of a one-click cloud update. An out-of-band patch shipped in May doesn’t mean every SharePoint instance running it was patched by June; it means the fix was available starting in May, and adoption from there follows whatever cadence each organization’s IT operations can sustain.

Attackers know this. A patched vulnerability with public technical details (even indirect ones, inferred from diffing the patch itself) becomes more, not less, useful to attack over time, because the pool of unpatched-but-known-vulnerable targets is easier to find than an actual zero-day. The three-day remediation window CISA set isn’t really a response to a new threat; it’s a response to the fact that a two-month-old patch clearly hadn’t reached saturation, and active exploitation was the signal that forced the issue.

The Bigger Shift: CISA Is Now Triaging by Risk, Not Treating Every KEV Entry the Same

A three-lane sorting funnel made of circuit-board lines separating vulnerability bug icons into risk tiers, with the shortest lane glowing gold for highest urgency

The three-day deadline itself reflects a change in how CISA structures urgency. Under Binding Operational Directive 26-04, which replaced the older blanket-deadline approach, agencies now face remediation timelines calibrated to actual risk factors rather than a single fixed window for every KEV entry. A vulnerability that checks every box — it gives an attacker total control of a publicly exposed system, it can be exploited automatically without human effort, and it’s confirmed in the KEV catalog — gets the shortest possible deadline: three days, plus a requirement that agencies perform forensic triage to determine whether they were already compromised before the patch went in. Lower-risk KEV entries get correspondingly longer windows. CVE-2026-45659 landed in the three-day tier because SharePoint’s exploitation path checks all three boxes: broad exposure, low attacker effort, confirmed active use.

The directive also sets a longer horizon: agencies have until December 7, 2026 to fully adopt this risk-based remediation posture across their environments, rather than treating BOD 26-04 as a one-time emergency response mechanism.

What This Actually Means for Anyone Running SharePoint

The practical takeaway isn’t “watch out for SharePoint” in the abstract — it’s that the population of organizations still running an unpatched instance of a bug fixed two months ago is apparently large enough that attackers found it worth exploiting at scale, and large enough that CISA felt the need for an emergency directive rather than routine advisory language. If a company’s patch cadence for enterprise collaboration software runs on a quarterly or “when we get to it” schedule, this is the kind of vulnerability that turns that gap into an active incident rather than a theoretical risk. The fix has existed since May. The only variable that changed between May and July was whether it got installed.

  • On May 16, 2026
  • 0 Comment
Tags: CISA, Microsoft, security, SharePoint, vulnerability management

Leave Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts
  • Why Load Test Numbers Lie
  • When Config Became Executable: The Twenty-Year Pattern Behind Supply Chain Attacks
  • How Software Became a Medical Device
  • Compliant With What? A Working Map of GDPR, HIPAA, SOC 2 and ISO 27001
  • Local AI vs Cloud AI: The Break-Even Is About Utilization, Not Tokens
Categories
  • ai (7)
  • android (18)
  • apple (36)
  • chart (18)
  • cloud (1)
  • fix (42)
  • games (11)
  • google (31)
  • hardware (73)
  • healthcare (3)
  • how to (231)
  • internet (92)
  • ios (23)
  • macos (3)
  • microsoft (82)
  • mobile (36)
  • news (74)
  • optimization (17)
  • osx (4)
  • outsourcing (8)
  • qa (3)
  • regulation (7)
  • review (120)
  • security (37)
  • software (159)
  • windows (150)
Archives
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • August 2025
  • March 2025
  • February 2025
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • March 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • June 2018
  • May 2018
  • April 2018
  • February 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
  • June 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • January 2017
  • December 2016
  • November 2016
  • October 2016
  • September 2016
  • August 2016
  • July 2016
  • June 2016
  • May 2016
  • April 2016
  • March 2016
  • February 2016
  • January 2016
  • December 2015
  • November 2015
  • October 2015
  • September 2015
  • July 2015
  • January 2015
Archives
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • August 2025
  • March 2025
  • February 2025
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • March 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • June 2018
  • May 2018
  • April 2018
  • February 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
  • June 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • January 2017
  • December 2016
  • November 2016
  • October 2016
  • September 2016
  • August 2016
  • July 2016
  • June 2016
  • May 2016
  • April 2016
  • March 2016
  • February 2016
  • January 2016
  • December 2015
  • November 2015
  • October 2015
  • September 2015
  • July 2015
  • January 2015

GDPR Regulators Just Finished Grading Europe on 'The Right to Be Forgotten.' Now They're Grading Honesty.

Previous thumb

FDA Just Redrew the Line for What Counts as a Medical Device — and a Lot of AI Health Products Just Landed on the Free Side

Next thumb
Scroll

Services

  • Software Development
  • Quality Assurance
  • Customer Support
  • Managed Services
  • 24/7 Emergency IT Support
  • Competency Center
  • Local AI Agent Development
  • Software as a Medical Device

Compliance

  • Compliance Audit
  • GDPR Compliance
  • What is GDPR
  • ISO 9001:2015 Certification

Company

  • About Us
  • All Services
  • Projects
  • Case Studies
  • Articles
  • Contact
About HiTech Service

With 10 year experience of working together, we have reached tangible synergetic effect in performance and productivity, which results in highest quality services and satisfied clients.

Privacy Policy   Cookie Policy

 

  • Facebook
  • X
  • LinkedIn
CONTACT INFO
  • 900 Foulk Rd, Suite 201, Wilmington, DE, USA, 19803
  • Kudryavs’kyi descent 5b, Kyiv, Ukraine, 04053
  • +1 646.844.5712 (US)
ISO 9001:2015 certificate issued to HiTech Service LLC by Veritas
RIPE Atlas logo, the network measurement community HiTech Service takes part in
BrainBasket Foundation logo, IT education initiative HiTech Service supports
HiTech Service LLC membership badge of the Hi-Tech Office Ukraine association Dun & Bradstreet verified business badge for HiTech Service LLC
YouTeam partner badge for HiTech Service LLC
Hitech Service LLC

Copyright 2026