CISA Confirms SharePoint Flaw Is Used in Ransomware Attacks
CISA has confirmed that a Microsoft SharePoint flaw tracked as CVE-2026-45659 is now being used in ransomware attacks.
Last month, CISA warned that a new SharePoint flaw is being exploited. The agency has now linked the high-severity vulnerability to ransomware campaigns targeting vulnerable SharePoint servers.
The flaw, tracked as CVE-2026-45659, has been considered actively exploited since early July. It was also one of the three emerging SharePoint flaws previously flagged by CISA.
CVE-2026-45659 can allow remote code execution
CVE-2026-45659 affects unpatched SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition.
The vulnerability stems from unsafe deserialization and can allow attackers with low privileges to execute arbitrary code on affected servers.
Microsoft previously described exploitation as relatively low complexity and said attackers need little prior knowledge of the targeted system.
CISA ordered federal agencies to patch the flaw
CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities Catalog on July 1 and gave Federal Civilian Executive Branch agencies three days to secure affected SharePoint servers.
The agency warned that vulnerabilities of this type frequently attract malicious actors and pose significant risks to federal organizations.
CISA later advised organizations to install Microsoft’s latest security updates, confirm that patches were successfully applied, monitor SharePoint servers for signs of compromise, and reduce patching delays.
Hundreds of SharePoint servers reportedly remain vulnerable
More than 200 SharePoint systems reportedly remain unpatched against CVE-2026-45659, leaving them exposed to potential attacks.
Microsoft has not yet updated its own CVE advisory to officially mark the vulnerability as exploited in the wild.
Meanwhile, in other security news, Microsoft warns of new StormEncryptor ransomware.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages