HIGH: Microsoft Patches SharePoint Deserialization RCE That Hands Site Members Server Code Execution
Microsoft patched CVE-2026-45659, an 8.8 CVSS deserialization remote code execution flaw in SharePoint Server Subscription Edition, 2019, and 2016. The bug only requires Site Member privileges, a trivially low bar given SharePoint history of being weaponized for mass exploitation.