Skip to content
The ColumnAnalysis· No. 2786

The SharePoint Flaw Microsoft Patched, Then Forgot to Announce

The American cybersecurity agency CISA added, on July 1, 2026, a critical vulnerability affecting MicrosoftSharePoint Server to its catalog of actively exploited

Premium reading
MadMax
Key takeaways
  1. The American cybersecurity agency CISA added, on July 1, 2026, a critical vulnerability affecting MicrosoftSharePoint Server to its catalog of actively exploited
  2. Introduction: a federal emergency born from an administrative slip
  3. A 72-hour deadline for the entire US government
Transparency

Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.

Introduction: a federal emergency born from an administrative slip

A 72-hour deadline for the entire US government

The American cybersecurity agency CISA added, on July 1, 2026, a critical vulnerability affecting MicrosoftSharePoint Server to its catalog of actively exploited flaws, with a remediation deadline set for July 4, 2026 for US federal civilian agencies, according to The Hacker News. Just three days to fix a flaw that, ironically, had already been patched for weeks without anyone really being told about it.

This vulnerability, tracked as CVE-2026-45659 with a severity score of CVSS 8.8 out of 10, allows remote code execution through an untrusted-data deserializationflaw, a type of technical vulnerability that remains one of the most dangerous in application security.

The detail that changes everything: a patch released without fanfare

What makes this story particularly revealing is that Microsoft had already fixed this flaw in its May 2026 update cycle, but only published the corresponding security bulletin on May 21, several weeks after the fix shipped, according to Threat-Modeling.com. Microsoft reportedly acknowledged itself having "forgotten to disclose the existence of the vulnerability."

This kind of disclosure delay, however unintentional, leaves security teams in the dark for critical weeks, a reality that should alarm anyone handling cybersecurity at a company or a government agency.

I find it stunning that a company the size of Microsoft, whose software runs hundreds of thousands of organizations worldwide, could simply "forget" to publish a security bulletin for nearly a month. This kind of administrative error has a price, and that price is measured in compromised servers.

The technical anatomy of a formidable flaw

How exploitation of CVE-2026-45659 works

The vulnerability relies on deserialization of untrusted data (tracked as CWE-502), a mechanism that lets an authenticated attacker execute arbitrary code on the SharePoint server simply by sending it specially crafted data, according to the Canadian Centre for Cyber Security. Attack complexity is rated low, meaning no deep prior knowledge of the target environment is required.

The access threshold required remains relatively low: an attacker only needs minimal Site Memberpermissions, an access level commonly granted to employees, contractors, and external partners in most enterprise SharePoint deployments, according to CybelAngel.

No human interaction needed for the attack

Perhaps the most concerning aspect of this flaw is that it requires no user interaction and no administrative privileges to be successfully exploited. An attacker with the minimum access level can act autonomously, with no need to convince anyone to click a link or open a booby-trapped document.

This technical trait turns an already serious vulnerability into a near-automated threat, one that can be exploited at scale by tools systematically scanning the internet for vulnerable SharePoint servers.

Whenever a flaw requires neither human interaction nor elevated privilege, I consider it deserves to be treated as an absolute emergency, regardless of the vendor's initial assessment. The history of cybersecurity is full of cases where "unlikely exploitation" turned out to be exactly the opposite.

The irony of Microsoft's initial assessment

"Exploitation less likely" disproven by the facts

Microsoft initially classified this vulnerability as showing "exploitation less likely," according to its own security advisory as cited by The Hacker News. This assessment, which likely influenced the priority many overstretched IT teams assigned to the fix, proved entirely wrong once evidence of active exploitation was confirmed by CISA.

This gap between the vendor's initial assessment and on-the-ground reality illustrates a recurring structural problem: technology companies often have an interest, consciously or not, in downplaying the perceived severity of their own flaws.

A history of underestimation at Microsoft

This is not the first time an initial Microsoft assessment of a SharePoint flaw has proven too optimistic. The CVE-2026-20963 vulnerability, added to the KEV catalog in March 2026, had its CVSS score raised and its description revised after Microsoft realized it could be exploited by an unauthenticated attacker, according to CERT-EU.

That March flaw, like the July one, targeted the same type of deserialization mechanism, a pattern that should push Microsoft to more fundamentally rethink SharePoint's security architecture rather than patching flaw after flaw reactively.

I notice a troubling pattern: this is not the first, and probably not the last, critical deserialization flaw in SharePoint this year. At some point, patching individual symptoms is no longer enough; the deep architectural cause needs to be addressed.

The race against the end-of-life clock

One deadline stacked on top of another

The timing of this alert is especially awkward: SharePoint Enterprise Server 2016 and SharePoint Server 2019, two of the versions affected by this flaw, officially reach end of life on July 14, 2026, just ten days after the remediation deadline imposed by CISA, according to the Canadian Centre for Cyber Security. After that date, Microsoft will stop publishing security fixes for these versions.

Organizations still running these aging versions therefore face an impossible choice within days: apply the fix immediately, migrate to a supported version on an extremely short timeline, or accept a permanent security risk after the end-of-life date.

Enterprise migrations that take months, not days

Anyone who has ever taken part in an enterprise platform migration knows this type of project usually takes months of planning, testing, and phased rollout, not ten days. This operational reality creates an impossible tension for many organizations caught between security urgency and the inevitable slowness of digital transformation processes.

I believe this situation should be a lesson for IT leadership teams that keep postponing, year after year, their migrations to supported versions, betting that "it will hold a bit longer."

I fully understand the budget constraints that push organizations to delay migrating critical systems. But this kind of compressed calendar, where urgent security and product end-of-life fall ten days apart, illustrates the concrete price of that technological procrastination.

What the scale of the attack surface reveals

SharePoint, the backbone of enterprise collaboration

Microsoft SharePoint Server remains one of the most widely deployed document management and collaboration platforms in the world, used by hundreds of thousands of organizations, from small businesses to the largest government agencies. This ubiquity turns every critical SharePoint flaw into a cybersecurity event on a global scale, well beyond the narrow circle of information security experts.

The versions affected by this specific flaw, namely SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016, cover a substantial share of the global SharePoint installed base still deployed on-premises rather than in the cloud.

The aggravating factor of third-party access

The permission level required to exploit this flaw, that of a simple Site Member, is commonly granted to contractors, business partners, and temporary employees in most enterprise environments, according to Daily Security Review. This reality considerably widens the pool of potential attackers capable of exploiting the flaw, well beyond system administrators alone.

This trait makes the flaw particularly dangerous in large organizations, where rigorous management of third-party access remains, in practice, a constant challenge for IT security teams.

I think this flaw perfectly illustrates why the principle of least privilege should be applied far more strictly in enterprise collaboration environments. Granting "Site Member" access should never, in practice, amount to handing over the keys to the server.

The coordinated response of Western agencies

A welcome transatlantic collaboration

CISA's alert was quickly echoed by the Canadian Centre for Cyber Security, which published its own detailed advisory including the exact version numbers needed to identify vulnerable systems and the fixed versions available. This coordination among Western agencies illustrates a positive side of the collective response to cross-border cyber threats.

I consider the speed of coordination between American and Canadian agencies an encouraging example of what should be the norm in a world where cyber threats completely ignore national borders.

The persistent limits of the US federal directive

The binding operational directive BOD 26-04, which imposes this three-day remediation window on US federal civilian agencies, only applies to the federal public sector, leaving private companies, local governments, and non-governmental organizations with no equivalent legal obligation to patch quickly.

This regulatory asymmetry means that, even after the July 4 deadline, a potentially large number of vulnerable SharePoint servers will continue to exist in the private sector, exposed to the same risks of active exploitation.

I believe the gap between federal public sector obligations and the absence of an equivalent requirement for the private sector represents a systemic flaw almost as significant as the technical vulnerability itself. National security in cyberspace does not stop at the doors of government agencies.

The summer 2025 precedent, a story repeating itself

A worrying seasonal pattern

This July 2026 SharePoint crisis strangely echoes the one from the previous summer: in July 2025, CISA had already given federal agencies an extremely short window, until the end of a Monday, to fix a critical zero-day vulnerability in SharePoint, a crisis that saw more than 9,000 vulnerable systems compromised worldwide according to figures compiled at the time.

This seasonal recurrence of major SharePoint crises, almost exactly a year apart, deserves to be documented as a pattern rather than dismissed as mere coincidence.

Lessons not learned from one year to the next

If the same types of deserialization vulnerabilities keep appearing year after year on the same platform, it raises a legitimate question about the depth of the internal security audits Microsoft conducts on its own SharePoint codebase, a decades-old product whose legacy architecture likely complicates any complete security modernization.

I think organizations that depend on SharePoint should now build this recurring pattern into their annual security planning, systematically scheduling heightened vigilance during the summer months.

Watching the same scenario repeat year after year, with the same types of flaws and the same rushed remediation deadlines, makes me wonder whether the tech industry truly learns from its own past crises, or simply manages each incident in isolation.

What this means for Western digital sovereignty

A structural dependence on a handful of vendors

This crisis illustrates, once again, the structural dependence of Western governments and companies on a small number of dominant technology vendors, of which Microsoft remains the most emblematic example. When a critical flaw hits a platform as widespread as SharePoint, a significant share of Western digital infrastructure finds itself simultaneously exposed.

This concentration of technological risk deserves broader strategic reflection on diversifying critical infrastructure, particularly for government agencies that manage sensitive data tied to national security.

Cybersecurity as a direct geopolitical issue

I consider the cybersecurity of Westerninfrastructure to be a front in its own right in the broader strategic competition with China, Russia, and other hostile state actors that actively exploit this type of vulnerability for industrial or state espionage. Every unpatched flaw in critical Western infrastructure represents a potential entry point for malicious actors backed by rival states.

The exact origin of the current exploitation of CVE-2026-45659 remains unknown at this stage, as CISA has not publicly attributed this campaign to a specific actor, but the recent history of SharePoint flaws has regularly involved groups backed by foreign states.

I remain convinced that the West chronically underinvests in the resilience of its critical digital infrastructure, even as our strategic rivals, China foremost among them, devote considerable resources to systematically exploiting our technological vulnerabilities.

The role of researchers and the security community

A monitoring ecosystem that works, against the odds

Credit must be given: the cybersecurity research ecosystem, including organizations such as CybelAngel, Aviatrix, and Threat-Modeling.com, reacted quickly to document, analyze, and share detailed information about this flaw as soon as it was added to CISA's KEV catalog. This collective responsiveness lets enterprise security teams quickly access precise technical information to prioritize their remediation efforts.

This speed of dissemination stands in stark contrast to Microsoft's slowness in publishing its own initial security bulletin, a paradox that illustrates the crucial importance of an independent cybersecurity research ecosystem.

The indispensable role of public databases

Resources like the US National Vulnerability Database (NVD) and CISA's KEV catalog play an indispensable role in public transparency, letting any organization, regardless of size or resources, freely access verified information about active threats.

This publicly funded information infrastructure, paid for by American taxpayers, deserves recognition as a public good essential to the collective security of the entire Western digital ecosystem.

I think these public vulnerability databases represent one of the best government investments in collective cybersecurity, a reassuring counterexample to the sometimes overly slow bureaucracy federal agencies are often accused of.

Practical recommendations for exposed organizations

Check, patch, migrate: the mandatory sequence

For any organization running an affected version of SharePoint Server, the first step is to immediately check the exact deployed version number using the Get-SPProduct -Local command, then apply the available fixes without delay, referenced under the identifiers KB5002863, KB5002868, and KB5002870 depending on the version involved.

Organizations unable to apply the fix immediately should, at a minimum, drastically limit their SharePoint servers' exposure to the internet, favoring exclusively internal access or a secure virtual private network until the update is complete.

Beyond the technical fix, an access review

I strongly recommend, beyond the simple technical fix, a full review of the permissions granted to Site Member-level user accounts, particularly for accounts belonging to contractors or external partners who do not necessarily need such broad access under normal circumstances.

This access review, though tedious, structurally reduces the attack surface available for this type of vulnerability, independent of the individual fixes Microsoft applies over time.

I believe rigorous user permission management should be treated with as much seriousness as applying the fixes themselves. Too many organizations treat access management as an administrative formality rather than a fundamental pillar of their security posture.

A tech industry under pressure to be transparent

The reputational price of a disclosure lapse

The episode of the security bulletin "forgotten" for nearly a month represents a significant reputational cost for Microsoft, in a context where trust in the transparency of major technology vendors is already weakened by years of similar incidents across the entire industry.

Enterprise customers and government agencies are entitled to demand stricter, faster disclosure standards, particularly for critical vulnerabilities affecting infrastructure as sensitive as enterprise document management platforms.

Toward stricter disclosure regulation

This incident could feed arguments in favor of stricter regulation imposing firm disclosure deadlines for critical vulnerabilities on technology vendors, a measure already discussed in several Western jurisdictions but rarely applied with the necessary rigor.

I believe this kind of incident, as frustrating as it is for the security teams involved, can paradoxically serve as a catalyst for regulatory reforms that benefit the entire Western digital ecosystem.

I sincerely believe stricter regulation on vulnerability disclosure timelines, even if it complicates life for tech giants, would better serve collective national security interests than the current situation, where every vendor manages transparency on its own internal schedule.

What this crisis reveals about security team burnout

An unsustainable patching pace

IT security teams, already facing a constant stream of alerts and fixes to apply, now have to manage ever-shorter remediation windows, sometimes just three days as in this case. This pace, while understandable given the urgency of active threats, contributes to professional burnout documented across the entire cybersecurity sector.

The pileup of these successive emergencies, SharePoint in March, then again in July, not to mention the countless other critical vulnerabilities affecting other platforms during the same period, illustrates the sheer scale of the workload placed on IT security professionals.

The urgent need for automation and additional resources

I believe this constant pressure justifies increased investment in automating patching and detection processes, along with a significant boost in cybersecurity staffing, in both the public and private sectors, across the entire Western world.

Without these structural investments, security teams will keep operating in a state of perpetual crisis management, an untenable situation in the long run against increasingly sophisticated and well-funded adversaries.

I think the chronic exhaustion of IT security teams is itself an underestimated national security risk. A burned-out analyst, overwhelmed by dozens of simultaneous urgent alerts, will inevitably let one slip through, and that flaw could be the most dangerous of all.

The invisible economic cost of a cybersecurity crisis

Overtime hours that show up in no budget

Behind every CISA alert lies an economic reality rarely quantified: entire IT teams mobilized on an emergency basis, often during a long American holiday weekend around July 4, to apply fixes that were not on their regular work calendar. This overtime, these external consultant contracts called in as reinforcement, these IT projects delayed to free up resources, represent a real economic cost that never appears in official statements from Microsoft or CISA.

For a small or medium-sized business without a full-time dedicated security team, this kind of emergency can represent a disproportionate budget shock, sometimes forcing reliance on external providers billed at emergency rates well above usual market prices.

The disproportionate burden on underfunded organizations

Municipal governments, regional hospitals, and small educational institutions, often among the most loyal users of older SharePoint Server versions deployed on-premises rather than in the cloud, are precisely the organizations least financially equipped to respond to this kind of emergency within three days.

This resource asymmetry between large technology companies with sophisticated security teams and small organizations with limited budgets creates a structural vulnerability gap that deserves particular attention from Western public policymakers.

I think uniform deadlines imposed on all organizations, regardless of size or resources, ignore a fundamental economic reality. A federal agency with a full-time security team is not in the same situation as a small municipality running its IT on a shoestring budget.

What end users should understand about this crisis

A technical vulnerability, but very concrete consequences

For the ordinary employee who uses SharePoint daily to share documents with colleagues, this technical crisis can seem abstract and distant. Yet if their organization fails to fix the flaw in time, the concrete consequences can include the theft of confidential documents, malware installed on the internal network, or a complete interruption of document collaboration services during emergency remediation.

I believe it is essential to make this kind of technical crisis accessible to the general public, because institutional cybersecurity is no longer a topic reserved for specialists: it directly affects the daily working lives of millions of Western workers who depend on these platforms without even knowing it.

Simple actions that make a real difference

While waiting for their IT department to apply the necessary fixes, employees can help limit risk by promptly reporting any unusual behavior on collaboration platforms, avoiding storing extremely sensitive information on potentially vulnerable systems, and scrupulously following the IT security guidance issued by their organization during this critical period.

This collective vigilance, though modest at the individual level, concretely helps shrink the exposure window during which an organization remains vulnerable to active exploitation of the flaw.

I find it important to point out that cybersecurity is never solely a matter for technical experts. Every employee who clicks, shares, or stores a document contributes, often unknowingly, to their organization's overall security posture.

Conclusion: a lesson that goes far beyond SharePoint

What this crisis teaches us collectively

This crisis around CVE-2026-45659 goes well beyond the technical scope of a single SharePoint flaw patched under pressure. It illustrates, with almost textbook clarity, the structural weaknesses of our collective cybersecurity ecosystem: slow vendor disclosure, excessive dependence on a small number of dominant platforms, regulatory asymmetry between the public and private sectors, and the growing exhaustion of the teams tasked with defending our digital infrastructure.

None of these problems will be solved by a single software fix, however urgent it is to apply the one available today for SharePoint.

A call for permanent, rather than episodic, vigilance

I close this analysis with a simple conviction: Western cybersecurity can no longer afford to operate reactively, sprinting from one three-day deadline to the next. It demands a structural overhaul of our investment priorities, our regulatory demands on technology vendors, and our support for the professionals who, every day, protect the infrastructure our collective digital sovereignty concretely depends on.

By July 14, the end-of-life date for two of the affected versions, every organization still exposed will have had to make its choice: patch, migrate, or accept a risk that recent days' news has made impossible to ignore.

I close this analysis with a simple observation: we will keep living through these repeated crises as long as Western cybersecurity is treated as a series of one-off emergencies rather than a permanent structural undertaking. CVE-2026-45659 will be forgotten in a few weeks, replaced by the next alert. The real test will be whether, this time, the collective lessons actually stick.

By Maxime Marquette, columnist

Columnist's transparency note

Who I am and my limits

I sign this analysis under the name Maxime Marquette. I am neither a cybersecurity engineer nor a Microsoft employee: my role is to synthesize and contextualize public technical information from government agencies and specialized security companies, for a readership that does not necessarily have time to read detailed technical advisories in English.

My method and acknowledged biases

I carry an acknowledged bias in favor of stricter cybersecurity regulation for major Western technology companies, without denying the strategic importance of those same companies in the face of international competition. I have no privileged access to internal Microsoft or CISA data, only to the technical publications made public.

Sources

Primary sources

Canadian Centre for Cyber Security, alert on the critical SharePoint vulnerability CVE-2026-45659 — July 2, 2026

Aviatrix, SharePoint RCE flaw now actively exploited — July 2, 2026

NVD, detailed technical record for CVE-2026-45659 — July 1, 2026

Secondary sources

The Register, Microsoft said exploitation was less likely, but CISA just added SharePoint RCE to the KEV list — July 2, 2026

CybelAngel, detailed analysis of the SharePoint flaw CVE-2026-45659 — July 3, 2026

The Hacker News, SharePoint RCE flaw added to the KEV catalog after active exploitation — July 2, 2026

Get the geopolitics analyses

Conflicts, powers, alliances: the MadMax thread without the noise.

Cite this article

Maxime Marquette (2026). The SharePoint Flaw Microsoft Patched, Then Forgot to Announce. MadMax. https://mad-max.co/en/article/la-faille-sharepoint-que-microsoft-a-patchee-puis-oubliee-d-annoncer

How does this piece make you feel?
MM
Maxime Marquette
Independent columnist

Maxime Marquette writes most of the analyses and columns published on MadMax — geopolitics, technology, and current events, no filler.

The Newsletter

Enjoyed this piece? Get the next one.

One chronicle a week, straight to your inbox. No noise.

Comments

0 / 2000

Be the first to weigh in.

This article was generated with AI assistance, under human supervision.

Analysis3655 words19 min read