Today's the Deadline. Does Your SharePoint Team Know It?
In late May, Microsoft shipped an out-of-band patch for a SharePoint Server flaw that lets an attacker with nothing more than basic "Site Member" access run code on your server. No admin rights required, no privilege escalation — just an authenticated login and a deserialization bug Microsoft itself rated as low complexity to exploit.
Five weeks later, on July 1, CISA confirmed someone is actually using it. The agency added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog and gave federal civilian agencies three business days to patch, under its Binding Operational Directive. That deadline is today.
I've spent a career watching organizations treat a patch release as the end of the story. It isn't. The patch existed for five weeks before CISA's warning made anyone outside Microsoft chase it down with urgency. In that window, every on-prem SharePoint Server running Subscription Edition, 2019, or 2016 sat exposed to anyone who could get one authenticated login — a contractor account, a phished employee, a vendor with portal access. Not an admin. A Site Member. That's most of your building.
The three-day number isn't about SharePoint
CISA's directive gives federal civilian agencies three days on a confirmed KEV exploit. Private companies don't answer to that directive, and most of you reading this don't run a three-day patch cycle for anything, let alone a document-collaboration platform half your company touches daily. Your actual patch cadence is probably monthly, maybe quarterly if the change board is slow and the app owner fights every maintenance window.
That gap — between what the federal government just told itself is urgent and what your organization actually does day to day — is the compliance-versus-security problem I wrote about in Cyber Risk Is Business Risk. Compliance asks whether you patched within your documented SLA. Security asks whether anyone is inside right now. Those are different questions on different clocks, and CVE-2026-45659 makes the difference concrete: Microsoft rated exploitation "less likely" when it shipped the fix. CISA's own KEV addition proves that assessment wrong. If your patch prioritization runs off vendor severity labels alone, you're inheriting someone else's guess.
Ask your CISO this week
I'd ask four things, in this order, and I'd want numbers back, not reassurance. First, do we run on-prem SharePoint Server — Subscription Edition, 2019, or 2016 — anywhere in the environment, including some forgotten instance a business unit stood up years ago? Second, is it patched against CVE-2026-45659 right now, today, not scheduled for the next maintenance window? Third, who holds Site Member access, and would we know if one of those accounts started acting strangely — new files, unusual process activity, outbound connections it's never made before? Fourth, what is our actual mean time to patch on a confirmed KEV entry, measured, not estimated?
That fourth question belongs in the boardroom, not just the CISO's office. It's a governance metric, not a technical one. If nobody on your board can tell you your organization's real patch velocity against CISA's KEV catalog, nobody is actually overseeing cyber risk. They're reviewing a slide someone built for the quarterly meeting.
Why this one is worth your attention
SharePoint has been a repeat target. Storm-2603, the threat actor behind Warlock ransomware, has been hitting on-prem SharePoint flaws since mid-2025, and Microsoft's own incident response team disclosed last month that a routine ransomware investigation turned up two unrelated attackers operating inside the same compromised network at the same time. Nobody has publicly attributed exploitation of this specific CVE to a named group yet, and CISA hasn't released details of what it's observed. That's not comfort. It means the visibility gap runs in both directions — attackers found this before defenders did, and defenders still don't fully know who's using it or why.
I don't think most executive teams need another vulnerability briefing. They need to stop treating "patched" as a status and start treating it as a question that gets asked and answered on a schedule shorter than the attacker's. CISA just modeled what that schedule looks like: three days. Compare that number to your last change-management cycle and decide for yourself whether the gap is one you're comfortable explaining after the fact.
