CISA Flags CVE-2026-45659 SharePoint Flaw: Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-21298, a critical Microsoft SharePoint Server vulnerability, to its Known Exploited Vulnerabilities (KEV) catalog. This deserialization flaw allows authenticated attackers to execute arbitrary code remotely on vulner