Cyber & Resilience - 6 min read - 14 July 2026

Microsoft said this SharePoint flaw was 'less likely' to be exploited. A federal network found out otherwise.

When Microsoft patched CVE-2026-45659 in May, it rated real-world exploitation "less likely." By July, CISA had added the flaw to its Known Exploited Vulnerabilities catalog and DHS had confirmed a breach of a sensitive information-sharing network that ran through a SharePoint system. The gap between the two ratings is the part worth studying.

CVE-2026-45659 is a deserialization flaw in Microsoft SharePoint Server, scoring 8.8 on CVSS, and it doesn't need much from an attacker to be useful. As The Hacker News reported, any authenticated attacker holding nothing more than Site Member permissions - the lowest tier of access most organisations hand out freely to anyone with a legitimate reason to touch a SharePoint site - can trigger remote code execution. No admin rights required. Microsoft shipped a fix in May 2026 across SharePoint Server Subscription Edition, SharePoint Server 2019 and SharePoint Enterprise Server 2016, and, as The Register flagged, rated the likelihood of exploitation "Less Likely" at the time. On 1 July, CISA added the flaw to its Known Exploited Vulnerabilities catalog after confirming active exploitation, and ordered federal civilian agencies to patch by 4 July - a five-week gap between "less likely" and "actively exploited in the wild," reported by BleepingComputer.

The breach the timeline points to

Around the same window, DHS confirmed that hackers had breached the Homeland Security Information Network, known as HSIN - a sensitive but unclassified platform used by federal, state, local, tribal, territorial and international partners, plus the private sector, to coordinate emergency response and share threat intelligence. Nextgov/FCW's reporting places the intrusion between late May and early June, and describes it as targeting both HSIN's own servers and a SharePoint system used for inter-agency collaboration. DHS has not publicly confirmed the intrusion vector was CVE-2026-45659 specifically, and has not yet attributed the attack or confirmed whether documents were taken. What is confirmed, and reported separately by Nextgov/FCW, is a detail that matters more than attribution: the intrusion was flagged and dismissed as a false positive twice before it was eventually confirmed as real.

That detail reframes the story. The interesting failure here isn't just "a severe SharePoint flaw got exploited." It's that a vendor's own severity rating and an internal detection process both, independently, underestimated the same risk before real-world events corrected both assessments. HSIN's role in coordinating security for major forthcoming events, including 2026 World Cup preparations, is exactly the kind of exposure that makes "less likely" a phrase worth treating with real scepticism going forward.

What "less likely" actually tells you, and what it doesn't

Vendor exploitability ratings are a genuinely useful input to patch prioritisation - most enterprises can't treat every CVE as a fire drill, and a reasonable triage process depends on some signal for sequencing. The problem is treating the rating as a statement about your risk rather than a general prediction made without knowledge of your specific environment. A "less likely" rating from Microsoft describes an assessment of exploitation techniques and public proof-of-concept availability at the time of patching - it says nothing about whether your SharePoint deployment has broad Site Member access handed out to contractors, whether your detection tooling would actually catch deserialization-based exploitation, or whether your organisation is a plausible target for the kind of actor who develops exploits quietly rather than publishing them.

The five-week gap between patch and confirmed active exploitation is also a reminder that "less likely" is a snapshot, not a forecast with a shelf life attached. Exploit development doesn't stop because a vendor's initial assessment was calm, and organisations that used the "less likely" label to justify a slower patch cycle for a flaw requiring only low-privilege access were making a bet the timeline didn't reward.

  • Audit how many accounts hold Site Member or equivalent low-tier access to your SharePoint environments - CVE-2026-45659 needed nothing more, and that access tier is usually granted far more liberally than admin rights.
  • Confirm CVE-2026-45659 is patched across every SharePoint Server Subscription Edition, 2019 and Enterprise Server 2016 instance in your estate, including any instances outside central IT's direct visibility.
  • Treat a vendor's "less likely" exploitation rating as one input to patch sequencing, not a reason to deprioritise a flaw that needs only low-privilege access and affects internet- or intranet-facing collaboration platforms.
  • Review whether your detection tooling has, in the past year, dismissed an alert as a false positive that a second look might have confirmed - and whether there's a defined trigger for re-examining a dismissed alert when new threat intelligence emerges.
  • If your organisation shares data through any inter-agency, inter-partner or supply chain collaboration platform, confirm what your own exposure would be if that platform - not your core systems - were the entry point, since that was exactly HSIN's role here.

Neither Microsoft's rating nor DHS's detection process were unreasonable on the information available at the time - that's precisely why the gap matters. Assessments made without your specific environment in view will sometimes be wrong in your specific environment's favour, and sometimes not. Want a second opinion on how your patch prioritisation process weighs vendor severity ratings against your own exposure? Email sales@halfteck.com.

Explore more resources

Browse our full library of enterprise cloud, software, data and AI content.

View all resources