Microsoft · Sharepoint Server · CVE-2026-45659
**Name of the Vulnerable Software and Affected Versions**
Microsoft SharePoint Server Subscription Edition versions prior to 16.0.19725.20280
Microsoft SharePoint Server 2019 versions prior to 16.0.10417.20128
Microsoft SharePoint Enterprise Server 2016 versions prior to 16.0.5552.1002
**Description**
An issue exists in Microsoft Office SharePoint due to the deserialization of untrusted data. Deserialization is the process of converting a data stream back into an object. This flaw allows an authenticated attacker with Site Member permissions to execute arbitrary code remotely over a network without requiring elevated privileges.
**Recommendations**
Update SharePoint Server Subscription Edition to build 16.0.19725.20280.
Update SharePoint Server 2019 to build 16.0.10417.20128.
Update SharePoint Enterprise Server 2016 to build 16.0.5552.1002.