SharePoint Server KEV Patch Playbook for Dallas Businesses

Patch and verify CVE-2026-45659 across SharePoint Server Subscription Edition, 2019, and 2016 without importing unrelated machine-key rotation steps into every response.

Back to Blog
(Updated )
2 min read
Conceptual isometric illustration of an on-premises SharePoint server farm being hardened under an urgent security patch alert

CVE-2026-45659 is an authenticated remote-code-execution vulnerability affecting supported on-premises SharePoint Server editions. CISA added it to the Known Exploited Vulnerabilities catalog on July 1, 2026. The appropriate baseline action is to apply Microsoft’s update and verify the farm—not automatically run machine-key rotation commands copied from a different SharePoint incident.

Current as of 2026-08-15

MSRC’s CVE-2026-45659 entry identifies SharePoint Server Subscription Edition, 2019, and 2016 as affected. CISA’s KEV catalog records known exploitation and the federal due date.

Decision summary

  • Patch every SharePoint server in the farm with Microsoft’s applicable update.
  • Do not treat generic SharePoint machine-key rotation as a mandatory CVE-2026-45659 step.
  • Preserve evidence and expand into incident response when compromise is suspected.
  • Validate version, prerequisites, command applicability, and rollback before any farm-wide operation.

Scope the farm before changing it

  • Record edition, build, role, and patch state for every SharePoint server.
  • Identify internet-facing web applications, reverse proxies, and authentication paths.
  • Confirm backup, recovery, and maintenance-window readiness.
  • Preserve ULS, IIS, Windows, identity, EDR, and perimeter logs for the relevant period.

Patch according to Microsoft’s release guidance

Use Microsoft’s May 2026 Office update index and the MSRC entry to resolve the correct update for each supported edition. Follow the farm’s approved SharePoint patch sequence, complete required configuration steps, and confirm all nodes report the intended build.

Separate remediation from incident response

The security update remediates the vulnerability. Hunting, isolation, credential rotation, and key rotation are incident-response actions whose scope depends on evidence. If logs or endpoint telemetry show suspicious access, treat the farm as potentially compromised and bring in qualified responders before destroying evidence.

Do not run unqualified machine-key commands

Microsoft documents Set-SPMachineKey and Update-SPMachineKey with specific applicability and semantics. A production command sequence must be version-correct, tested, reviewed, scheduled, and paired with rollback. This article intentionally does not provide a generic copy-and-paste farm command block.

Verify closure

  • All farm servers run the required supported build.
  • Farm health, search, authentication, workflows, and integrations pass smoke tests.
  • No unexpected web shells, processes, scheduled tasks, accounts, or configuration changes are found.
  • Security telemetry and log retention are sufficient for the exposure window.
  • Rollback artifacts and incident decisions are documented.

For related guidance from ITECS, see ITECS Microsoft 365 consulting.

Sources and update trigger

Review trigger: Recheck when Microsoft revises CVE guidance, publishes a superseding update, or incident evidence changes the required response.

continue reading

More ITECS blog articles

Browse all articles

About ITECS Team

The ITECS team consists of experienced IT professionals dedicated to delivering enterprise-grade technology solutions and insights to businesses in Dallas and beyond.

View full profile and articles

Share This Article

Continue Reading

Explore more insights and technology trends from ITECS

View All Articles