Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2026-45454 — Microsoft SharePoint Server Upload Page Folder Path Traversal to Remote Code Execution

Summary

CVE-2026-45454: path traversal in SharePoint's Upload.aspx lets an authenticated attacker write into restricted libraries like the Master Page Gallery, escalating to RCE via ASPX webshells.
CVE
CVE-2026-45454
Published
Collected

original ↗