decrypted · 6 july 2026 · vulnerabilities and patching

The SharePoint patch that wasn't in the patch notes

A remote code execution flaw in on-premises Microsoft SharePoint has just been added to the US Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalogue, confirming what Microsoft itself thought unlikely: that CVE-2026-45659 is being actively used against real servers. The bug matters less for its mechanics, an insecure deserialisation flaw letting anyone with basic Site Member access run code on the server, than for how it got here. Microsoft shipped the fix back in May, then left the CVE out of its own release notes, correcting the oversight only days later. Organisations that did the sensible thing, reading the changelog to decide what to prioritise, had every reason to believe there was nothing SharePoint-shaped to worry about.

When the changelog lies by omission

This is where Secure by Design earns its keep as more than a slogan. The vulnerability class itself, deserialising untrusted data into executable objects, is a known, named category of flaw that architecture can largely design away; SharePoint has form here. But the more interesting failure is upstream of the code: a vendor's disclosure process is part of its security design, not an administrative afterthought. If patch severity and scope cannot be trusted from the release notes, every downstream patching decision an IT team makes is built on sand. For UK organisations still running SharePoint Server on-premises, the practical lesson is dull but firm: treat vendor "less likely to be exploited" ratings as opinion, not guarantee, and reconcile what you have actually installed against what a vendor says it patched, rather than against what it says was needed.

The patch wave, arriving on schedule

Back in May, the NCSC's chief technology officer Ollie Whitehouse warned UK organisations to brace for what he called a "patch wave": a forced reckoning with accumulated technical debt, driven by AI tools making it cheaper to find vulnerabilities that have sat undiscovered in old code for years. His advice was to identify and shrink internet-facing attack surface first, build the capacity to patch quickly and often including through supply chains, and treat patching as one part of a wider resilience picture rather than the whole job. The SharePoint episode is a useful, low-tech preview of exactly the problem he described, minus the AI. If a single mis-filed release note can leave organisations exposed for weeks without any acceleration from artificial intelligence at all, the case for building patch capacity now, before the AI-assisted version of this arrives at scale, looks rather less theoretical. NCSC also spent the spring pressing organisations to patch critical, unauthenticated flaws in internet-facing remote access gateways, the exact category Whitehouse's advice tells you to fix first.

AI finds bugs for both sides

On last week's Security Now, Steve Gibson walked through how iterative, "looping" techniques are what actually makes AI models good at hunting for vulnerabilities at scale, and noted that script kiddies are already turning the same trick on real targets. The same week, OpenAI went public with its own version of the idea aimed the other way: a scheme called Patch the Planet, using its most security-capable models alongside human reviewers at Trail of Bits to find and help fix flaws in widely used open source projects such as curl and Python before anyone malicious gets there first. Both stories describe the same underlying capability. Whether it nets out in defenders' favour depends entirely on who has the budget and the access to run it continuously, and open source maintainers historically have neither in abundance.

None of this changes what UK organisations should actually do this week, which is unglamorous: know what SharePoint, Citrix and other internet-facing systems you run, patch them against what vendors actually shipped rather than what their notes claimed, and assume the next wave of disclosures will be bigger and faster than this one. Secure by Design was never only about the code. It is about whether the whole supply chain, vendor disclosure included, is built so that doing the sensible thing is enough to keep you safe.

Sources

If your organisation needs help getting ahead of the next patch wave rather than reacting to it, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.