US cyber agency warns over forgotten SharePoint flaw
A recently identified but accidentally unpublicised remote code execution (RCE) flaw in Microsoft SharePoint, tracked as CVE-2026-45659, has been added to the US Cybersecurity and Infrastructure Security Agency’s (Cisa’s) Known Exploited Vulnerabilities (Kev) catalogue after evidence of active exploitation in the wild was identified. Microsoft is understood to have made a patch for CVE-2026-45649…