CVE-2026-45659 is an authenticated remote-code-execution vulnerability affecting supported on-premises SharePoint Server editions. CISA added it to the Known Exploited Vulnerabilities catalog on July 1, 2026. The appropriate baseline action is to apply Microsoft’s update and verify the farm—not automatically run machine-key rotation commands copied from a different SharePoint incident.
Current as of 2026-08-15
MSRC’s CVE-2026-45659 entry identifies SharePoint Server Subscription Edition, 2019, and 2016 as affected. CISA’s KEV catalog records known exploitation and the federal due date.
Decision summary
- Patch every SharePoint server in the farm with Microsoft’s applicable update.
- Do not treat generic SharePoint machine-key rotation as a mandatory CVE-2026-45659 step.
- Preserve evidence and expand into incident response when compromise is suspected.
- Validate version, prerequisites, command applicability, and rollback before any farm-wide operation.
Scope the farm before changing it
- Record edition, build, role, and patch state for every SharePoint server.
- Identify internet-facing web applications, reverse proxies, and authentication paths.
- Confirm backup, recovery, and maintenance-window readiness.
- Preserve ULS, IIS, Windows, identity, EDR, and perimeter logs for the relevant period.
Patch according to Microsoft’s release guidance
Use Microsoft’s May 2026 Office update index and the MSRC entry to resolve the correct update for each supported edition. Follow the farm’s approved SharePoint patch sequence, complete required configuration steps, and confirm all nodes report the intended build.
Separate remediation from incident response
The security update remediates the vulnerability. Hunting, isolation, credential rotation, and key rotation are incident-response actions whose scope depends on evidence. If logs or endpoint telemetry show suspicious access, treat the farm as potentially compromised and bring in qualified responders before destroying evidence.
Do not run unqualified machine-key commands
Microsoft documents Set-SPMachineKey and Update-SPMachineKey with specific applicability and semantics. A production command sequence must be version-correct, tested, reviewed, scheduled, and paired with rollback. This article intentionally does not provide a generic copy-and-paste farm command block.
Verify closure
- All farm servers run the required supported build.
- Farm health, search, authentication, workflows, and integrations pass smoke tests.
- No unexpected web shells, processes, scheduled tasks, accounts, or configuration changes are found.
- Security telemetry and log retention are sufficient for the exposure window.
- Rollback artifacts and incident decisions are documented.
For related guidance from ITECS, see ITECS Microsoft 365 consulting.
Sources and update trigger
- Microsoft MSRC — CVE-2026-45659
- Microsoft Support — May 2026 Office updates
- CISA — Known Exploited Vulnerabilities JSON
- Microsoft Learn — Set-SPMachineKey
- Microsoft Learn — Update-SPMachineKey
Review trigger: Recheck when Microsoft revises CVE guidance, publishes a superseding update, or incident evidence changes the required response.
continue reading
More ITECS blog articles
About ITECS Team
The ITECS team consists of experienced IT professionals dedicated to delivering enterprise-grade technology solutions and insights to businesses in Dallas and beyond.
View full profile and articles