Microsoft published security advisories for several remote code execution vulnerabilities affecting SharePoint, Microsoft Edge (Chromium-based), Azure Orbital Spatio, Azure Virtual Network Gateway, and Microsoft Power Pages, including CVE-2026-45659, CVE-2026-45495, CVE-2026-40412, CVE-2026-40411, and CVE-2026-23652. The most detailed disclosures focused on SharePoint Server, where Microsoft described CVE-2026-35439 and CVE-2026-40357 as deserialization of untrusted data flaws that could let authenticated attackers execute arbitrary code over the network on vulnerable servers.
Microsoft rated both SharePoint issues Important with CVSS 8.8 and said exploitation requires valid access, with CVE-2026-35439 requiring at least Site Owner privileges and CVE-2026-40357 requiring Site Member permissions. The company said neither flaw had been publicly disclosed or exploited in the wild at publication and assessed exploitation as less likely, while providing fixes that also apply to both SharePoint Server 2016 and SharePoint Enterprise Server 2016. Microsoft also disclosed CVE-2026-40362, an Excel heap-based buffer overflow that can lead to remote code execution if a user opens a malicious Office file; Microsoft said the Preview Pane is not an attack vector and that a patch is available.
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft released an out-of-band fix for CVE-2026-45659, a SharePoint Server remote code execution flaw exploitable by an authenticated attacker with Site Member permissions. The vulnerability was attributed to deserialization of untrusted data and, at the time of reporting, Microsoft said there was no public exploit code or known in-the-wild exploitation.
Microsoft published Security Update Guide entries for CVE-2026-45659 (Microsoft SharePoint), CVE-2026-40412 (Azure Orbital Spatio), CVE-2026-40411 (Azure Virtual Network Gateway), and CVE-2026-23652 (Microsoft Power Pages), all described as remote code execution vulnerabilities. The provided references do not include further technical or exploitation details.
Microsoft added a Security Update Guide entry for CVE-2026-45495, a remote code execution vulnerability in Chromium-based Microsoft Edge. The reference content provides no additional synopsis beyond the advisory publication.
Microsoft published Security Update Guide entries for CVE-2026-35439 and CVE-2026-40357 affecting Microsoft SharePoint Server, and CVE-2026-40362 affecting Microsoft Excel. Microsoft said fixes were available and that none of the flaws were publicly disclosed or exploited in the wild at publication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
16 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourceccb.belgium.be
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourcesupport.microsoft.com
Open sourcesupport.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.