Skip to main content

Actively exploited

Listed in CISA’s Known Exploited Vulnerabilities catalog since July 1, 2026.

CVE-2026-45659

Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

Microsoft · SharePoint Server

Published July 21, 2026

What happened

Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.

What it means for your business

Microsoft SharePoint Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-45659). Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network. CISA remediation due date: 2026-07-04. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Required action

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA due date: July 4, 2026

Sources

Related briefs

Actively exploited (KEV)

CVE-2026-56164

Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

Microsoft SharePoint Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-56164). Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network. CISA remediation due date: 2026-07-17. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft · SharePoint Server
Actively exploited (KEV)

CVE-2026-56155

Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

Microsoft Active Directory Federation Services is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-56155). Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally. CISA remediation due date: 2026-07-28. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft · Active Directory Federation Services
Actively exploited (KEV)

CVE-2026-58644

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-58644). Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. CISA remediation due date: 2026-07-19. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft · SharePoint
Actively exploited (KEV)

CVE-2021-27137

DD-WRT Stack-Based Buffer Overflow Vulnerability

DD-WRT DD-WRT is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-27137). DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability. CISA remediation due date: 2026-07-24. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

DD-WRT · DD-WRT

Need help patching?

PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.