The SharePoint Flaw Microsoft Patched, Then Forgot to Announce
The American cybersecurity agency CISA added, on July 1, 2026, a critical vulnerability affecting MicrosoftSharePoint Server to its catalog of actively exploited
- The American cybersecurity agency CISA added, on July 1, 2026, a critical vulnerability affecting MicrosoftSharePoint Server to its catalog of actively exploited
- Introduction: a federal emergency born from an administrative slip
- A 72-hour deadline for the entire US government
Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.
Introduction: a federal emergency born from an administrative slip
A 72-hour deadline for the entire US government
The American cybersecurity agency CISA added, on July 1, 2026, a critical vulnerability affecting MicrosoftSharePoint Server to its catalog of actively exploited flaws, with a remediation deadline set for July 4, 2026 for US federal civilian agencies, according to The Hacker News. Just three days to fix a flaw that, ironically, had already been patched for weeks without anyone really being told about it.
This vulnerability, tracked as CVE-2026-45659 with a severity score of CVSS 8.8 out of 10, allows remote code execution through an untrusted-data deserializationflaw, a type of technical vulnerability that remains one of the most dangerous in application security.
The detail that changes everything: a patch released without fanfare
What makes this story particularly revealing is that Microsoft had already fixed this flaw in its May 2026 update cycle, but only published the corresponding security bulletin on May 21, several weeks after the fix shipped, according to Threat-Modeling.com. Microsoft reportedly acknowledged itself having "forgotten to disclose the existence of the vulnerability."
This kind of disclosure delay, however unintentional, leaves security teams in the dark for critical weeks, a reality that should alarm anyone handling cybersecurity at a company or a government agency.
The technical anatomy of a formidable flaw
How exploitation of CVE-2026-45659 works
The vulnerability relies on deserialization of untrusted data (tracked as CWE-502), a mechanism that lets an authenticated attacker execute arbitrary code on the SharePoint server simply by sending it specially crafted data, according to the Canadian Centre for Cyber Security. Attack complexity is rated low, meaning no deep prior knowledge of the target environment is required.
The access threshold required remains relatively low: an attacker only needs minimal Site Memberpermissions, an access level commonly granted to employees, contractors, and external partners in most enterprise SharePoint deployments, according to CybelAngel.
No human interaction needed for the attack
Perhaps the most concerning aspect of this flaw is that it requires no user interaction and no administrative privileges to be successfully exploited. An attacker with the minimum access level can act autonomously, with no need to convince anyone to click a link or open a booby-trapped document.
This technical trait turns an already serious vulnerability into a near-automated threat, one that can be exploited at scale by tools systematically scanning the internet for vulnerable SharePoint servers.
The irony of Microsoft's initial assessment
"Exploitation less likely" disproven by the facts
Microsoft initially classified this vulnerability as showing "exploitation less likely," according to its own security advisory as cited by The Hacker News. This assessment, which likely influenced the priority many overstretched IT teams assigned to the fix, proved entirely wrong once evidence of active exploitation was confirmed by CISA.
This gap between the vendor's initial assessment and on-the-ground reality illustrates a recurring structural problem: technology companies often have an interest, consciously or not, in downplaying the perceived severity of their own flaws.
A history of underestimation at Microsoft
This is not the first time an initial Microsoft assessment of a SharePoint flaw has proven too optimistic. The CVE-2026-20963 vulnerability, added to the KEV catalog in March 2026, had its CVSS score raised and its description revised after Microsoft realized it could be exploited by an unauthenticated attacker, according to CERT-EU.
That March flaw, like the July one, targeted the same type of deserialization mechanism, a pattern that should push Microsoft to more fundamentally rethink SharePoint's security architecture rather than patching flaw after flaw reactively.
The race against the end-of-life clock
One deadline stacked on top of another
The timing of this alert is especially awkward: SharePoint Enterprise Server 2016 and SharePoint Server 2019, two of the versions affected by this flaw, officially reach end of life on July 14, 2026, just ten days after the remediation deadline imposed by CISA, according to the Canadian Centre for Cyber Security. After that date, Microsoft will stop publishing security fixes for these versions.
Organizations still running these aging versions therefore face an impossible choice within days: apply the fix immediately, migrate to a supported version on an extremely short timeline, or accept a permanent security risk after the end-of-life date.
Enterprise migrations that take months, not days
Anyone who has ever taken part in an enterprise platform migration knows this type of project usually takes months of planning, testing, and phased rollout, not ten days. This operational reality creates an impossible tension for many organizations caught between security urgency and the inevitable slowness of digital transformation processes.
Discover
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
FACT-CHECK: Kumamoto, a Magnitude 7.1 Earthquake Reopens the Seismic…
On July 28, 2026 , a magnitude 7.1 earthquake struck the…
FACT-CHECK: Bloody Hazing, a Secret Service Agent Faces Justice
A U.S. Secret Service agent stationed in South Florida was arrested…
I believe this situation should be a lesson for IT leadership teams that keep postponing, year after year, their migrations to supported versions, betting that "it will hold a bit longer."
What the scale of the attack surface reveals
SharePoint, the backbone of enterprise collaboration
Microsoft SharePoint Server remains one of the most widely deployed document management and collaboration platforms in the world, used by hundreds of thousands of organizations, from small businesses to the largest government agencies. This ubiquity turns every critical SharePoint flaw into a cybersecurity event on a global scale, well beyond the narrow circle of information security experts.
The versions affected by this specific flaw, namely SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016, cover a substantial share of the global SharePoint installed base still deployed on-premises rather than in the cloud.
The aggravating factor of third-party access
The permission level required to exploit this flaw, that of a simple Site Member, is commonly granted to contractors, business partners, and temporary employees in most enterprise environments, according to Daily Security Review. This reality considerably widens the pool of potential attackers capable of exploiting the flaw, well beyond system administrators alone.
This trait makes the flaw particularly dangerous in large organizations, where rigorous management of third-party access remains, in practice, a constant challenge for IT security teams.
The coordinated response of Western agencies
A welcome transatlantic collaboration
CISA's alert was quickly echoed by the Canadian Centre for Cyber Security, which published its own detailed advisory including the exact version numbers needed to identify vulnerable systems and the fixed versions available. This coordination among Western agencies illustrates a positive side of the collective response to cross-border cyber threats.
I consider the speed of coordination between American and Canadian agencies an encouraging example of what should be the norm in a world where cyber threats completely ignore national borders.
The persistent limits of the US federal directive
The binding operational directive BOD 26-04, which imposes this three-day remediation window on US federal civilian agencies, only applies to the federal public sector, leaving private companies, local governments, and non-governmental organizations with no equivalent legal obligation to patch quickly.
This regulatory asymmetry means that, even after the July 4 deadline, a potentially large number of vulnerable SharePoint servers will continue to exist in the private sector, exposed to the same risks of active exploitation.
The summer 2025 precedent, a story repeating itself
A worrying seasonal pattern
This July 2026 SharePoint crisis strangely echoes the one from the previous summer: in July 2025, CISA had already given federal agencies an extremely short window, until the end of a Monday, to fix a critical zero-day vulnerability in SharePoint, a crisis that saw more than 9,000 vulnerable systems compromised worldwide according to figures compiled at the time.
This seasonal recurrence of major SharePoint crises, almost exactly a year apart, deserves to be documented as a pattern rather than dismissed as mere coincidence.
Lessons not learned from one year to the next
If the same types of deserialization vulnerabilities keep appearing year after year on the same platform, it raises a legitimate question about the depth of the internal security audits Microsoft conducts on its own SharePoint codebase, a decades-old product whose legacy architecture likely complicates any complete security modernization.
I think organizations that depend on SharePoint should now build this recurring pattern into their annual security planning, systematically scheduling heightened vigilance during the summer months.
What this means for Western digital sovereignty
A structural dependence on a handful of vendors
This crisis illustrates, once again, the structural dependence of Western governments and companies on a small number of dominant technology vendors, of which Microsoft remains the most emblematic example. When a critical flaw hits a platform as widespread as SharePoint, a significant share of Western digital infrastructure finds itself simultaneously exposed.
This concentration of technological risk deserves broader strategic reflection on diversifying critical infrastructure, particularly for government agencies that manage sensitive data tied to national security.
Cybersecurity as a direct geopolitical issue
I consider the cybersecurity of Westerninfrastructure to be a front in its own right in the broader strategic competition with China, Russia, and other hostile state actors that actively exploit this type of vulnerability for industrial or state espionage. Every unpatched flaw in critical Western infrastructure represents a potential entry point for malicious actors backed by rival states.
The exact origin of the current exploitation of CVE-2026-45659 remains unknown at this stage, as CISA has not publicly attributed this campaign to a specific actor, but the recent history of SharePoint flaws has regularly involved groups backed by foreign states.
The role of researchers and the security community
A monitoring ecosystem that works, against the odds
Credit must be given: the cybersecurity research ecosystem, including organizations such as CybelAngel, Aviatrix, and Threat-Modeling.com, reacted quickly to document, analyze, and share detailed information about this flaw as soon as it was added to CISA's KEV catalog. This collective responsiveness lets enterprise security teams quickly access precise technical information to prioritize their remediation efforts.
This speed of dissemination stands in stark contrast to Microsoft's slowness in publishing its own initial security bulletin, a paradox that illustrates the crucial importance of an independent cybersecurity research ecosystem.
The indispensable role of public databases
Resources like the US National Vulnerability Database (NVD) and CISA's KEV catalog play an indispensable role in public transparency, letting any organization, regardless of size or resources, freely access verified information about active threats.
This publicly funded information infrastructure, paid for by American taxpayers, deserves recognition as a public good essential to the collective security of the entire Western digital ecosystem.
Practical recommendations for exposed organizations
Check, patch, migrate: the mandatory sequence
For any organization running an affected version of SharePoint Server, the first step is to immediately check the exact deployed version number using the Get-SPProduct -Local command, then apply the available fixes without delay, referenced under the identifiers KB5002863, KB5002868, and KB5002870 depending on the version involved.
Organizations unable to apply the fix immediately should, at a minimum, drastically limit their SharePoint servers' exposure to the internet, favoring exclusively internal access or a secure virtual private network until the update is complete.
Beyond the technical fix, an access review
I strongly recommend, beyond the simple technical fix, a full review of the permissions granted to Site Member-level user accounts, particularly for accounts belonging to contractors or external partners who do not necessarily need such broad access under normal circumstances.
This access review, though tedious, structurally reduces the attack surface available for this type of vulnerability, independent of the individual fixes Microsoft applies over time.
A tech industry under pressure to be transparent
The reputational price of a disclosure lapse
The episode of the security bulletin "forgotten" for nearly a month represents a significant reputational cost for Microsoft, in a context where trust in the transparency of major technology vendors is already weakened by years of similar incidents across the entire industry.
Enterprise customers and government agencies are entitled to demand stricter, faster disclosure standards, particularly for critical vulnerabilities affecting infrastructure as sensitive as enterprise document management platforms.
On the same topic
TESTIMONY: Assam, 700,000 Displaced and a State Rebuilding Every…
On July 20, 2026 , Al Jazeera reported that at least…
OPINION: Merz Under Fire as the CDU Learns the…
On July 29, 2026 , Le Monde describes an " unprecedented…
INVESTIGATION: Epstein a Foreign Agent? The Letter That Moves…
On July 21, 2026 , Jamie Raskin, Ranking Member of the…
Toward stricter disclosure regulation
This incident could feed arguments in favor of stricter regulation imposing firm disclosure deadlines for critical vulnerabilities on technology vendors, a measure already discussed in several Western jurisdictions but rarely applied with the necessary rigor.
I believe this kind of incident, as frustrating as it is for the security teams involved, can paradoxically serve as a catalyst for regulatory reforms that benefit the entire Western digital ecosystem.
What this crisis reveals about security team burnout
An unsustainable patching pace
IT security teams, already facing a constant stream of alerts and fixes to apply, now have to manage ever-shorter remediation windows, sometimes just three days as in this case. This pace, while understandable given the urgency of active threats, contributes to professional burnout documented across the entire cybersecurity sector.
The pileup of these successive emergencies, SharePoint in March, then again in July, not to mention the countless other critical vulnerabilities affecting other platforms during the same period, illustrates the sheer scale of the workload placed on IT security professionals.
The urgent need for automation and additional resources
I believe this constant pressure justifies increased investment in automating patching and detection processes, along with a significant boost in cybersecurity staffing, in both the public and private sectors, across the entire Western world.
Without these structural investments, security teams will keep operating in a state of perpetual crisis management, an untenable situation in the long run against increasingly sophisticated and well-funded adversaries.
The invisible economic cost of a cybersecurity crisis
Overtime hours that show up in no budget
Behind every CISA alert lies an economic reality rarely quantified: entire IT teams mobilized on an emergency basis, often during a long American holiday weekend around July 4, to apply fixes that were not on their regular work calendar. This overtime, these external consultant contracts called in as reinforcement, these IT projects delayed to free up resources, represent a real economic cost that never appears in official statements from Microsoft or CISA.
For a small or medium-sized business without a full-time dedicated security team, this kind of emergency can represent a disproportionate budget shock, sometimes forcing reliance on external providers billed at emergency rates well above usual market prices.
The disproportionate burden on underfunded organizations
Municipal governments, regional hospitals, and small educational institutions, often among the most loyal users of older SharePoint Server versions deployed on-premises rather than in the cloud, are precisely the organizations least financially equipped to respond to this kind of emergency within three days.
This resource asymmetry between large technology companies with sophisticated security teams and small organizations with limited budgets creates a structural vulnerability gap that deserves particular attention from Western public policymakers.
What end users should understand about this crisis
A technical vulnerability, but very concrete consequences
For the ordinary employee who uses SharePoint daily to share documents with colleagues, this technical crisis can seem abstract and distant. Yet if their organization fails to fix the flaw in time, the concrete consequences can include the theft of confidential documents, malware installed on the internal network, or a complete interruption of document collaboration services during emergency remediation.
I believe it is essential to make this kind of technical crisis accessible to the general public, because institutional cybersecurity is no longer a topic reserved for specialists: it directly affects the daily working lives of millions of Western workers who depend on these platforms without even knowing it.
Simple actions that make a real difference
While waiting for their IT department to apply the necessary fixes, employees can help limit risk by promptly reporting any unusual behavior on collaboration platforms, avoiding storing extremely sensitive information on potentially vulnerable systems, and scrupulously following the IT security guidance issued by their organization during this critical period.
This collective vigilance, though modest at the individual level, concretely helps shrink the exposure window during which an organization remains vulnerable to active exploitation of the flaw.
More analysis
ANALYSIS: Gaza's Phase Two, a Ceasefire Stalled in Cairo
On July 28, 2026 , a Hamas delegation left for Cairo…
FACT-CHECK: Kumamoto, a Magnitude 7.1 Earthquake Reopens the Seismic…
On July 28, 2026 , a magnitude 7.1 earthquake struck the…
FACT-CHECK: Bloody Hazing, a Secret Service Agent Faces Justice
A U.S. Secret Service agent stationed in South Florida was arrested…
Conclusion: a lesson that goes far beyond SharePoint
What this crisis teaches us collectively
This crisis around CVE-2026-45659 goes well beyond the technical scope of a single SharePoint flaw patched under pressure. It illustrates, with almost textbook clarity, the structural weaknesses of our collective cybersecurity ecosystem: slow vendor disclosure, excessive dependence on a small number of dominant platforms, regulatory asymmetry between the public and private sectors, and the growing exhaustion of the teams tasked with defending our digital infrastructure.
None of these problems will be solved by a single software fix, however urgent it is to apply the one available today for SharePoint.
A call for permanent, rather than episodic, vigilance
I close this analysis with a simple conviction: Western cybersecurity can no longer afford to operate reactively, sprinting from one three-day deadline to the next. It demands a structural overhaul of our investment priorities, our regulatory demands on technology vendors, and our support for the professionals who, every day, protect the infrastructure our collective digital sovereignty concretely depends on.
By July 14, the end-of-life date for two of the affected versions, every organization still exposed will have had to make its choice: patch, migrate, or accept a risk that recent days' news has made impossible to ignore.
By Maxime Marquette, columnist
Columnist's transparency note
Who I am and my limits
I sign this analysis under the name Maxime Marquette. I am neither a cybersecurity engineer nor a Microsoft employee: my role is to synthesize and contextualize public technical information from government agencies and specialized security companies, for a readership that does not necessarily have time to read detailed technical advisories in English.
My method and acknowledged biases
I carry an acknowledged bias in favor of stricter cybersecurity regulation for major Western technology companies, without denying the strategic importance of those same companies in the face of international competition. I have no privileged access to internal Microsoft or CISA data, only to the technical publications made public.
Sources
Primary sources
Canadian Centre for Cyber Security, alert on the critical SharePoint vulnerability CVE-2026-45659 — July 2, 2026
Aviatrix, SharePoint RCE flaw now actively exploited — July 2, 2026
NVD, detailed technical record for CVE-2026-45659 — July 1, 2026
Secondary sources
The Register, Microsoft said exploitation was less likely, but CISA just added SharePoint RCE to the KEV list — July 2, 2026
CybelAngel, detailed analysis of the SharePoint flaw CVE-2026-45659 — July 3, 2026
The Hacker News, SharePoint RCE flaw added to the KEV catalog after active exploitation — July 2, 2026
Get the geopolitics analyses
Conflicts, powers, alliances: the MadMax thread without the noise.
Cite this article
Maxime Marquette (2026). The SharePoint Flaw Microsoft Patched, Then Forgot to Announce. MadMax. https://mad-max.co/en/article/la-faille-sharepoint-que-microsoft-a-patchee-puis-oubliee-d-annoncer
Enjoyed this piece? Get the next one.
One chronicle a week, straight to your inbox. No noise.
This article was generated with AI assistance, under human supervision.
Comments
Be the first to weigh in.