Skip to main content
Emerging ThreatsMalware & Ransomware

Ransomware gangs exploit Microsoft SharePoint flaw

Rows of computer servers and storage systems in a brightly-lit server room.

CVE-2026-45659 — a high-severity Microsoft SharePoint remote code execution vulnerability — has been flagged as actively exploited since early July and, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA), is now being abused by ransomware gangs.

CVE-2026-45659 and Microsoft's published fixes

The fault tracked as CVE-2026-45659 stems from a deserialization of untrusted data weakness that allows a low-privileged attacker to execute arbitrary code on unpatched SharePoint servers. Microsoft published security updates in May for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. As Microsoft put it when releasing those updates, "an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component."

CISA's KEV action and the federal three-day order

CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities Catalog (KEV) on July 1 and ordered Federal Civilian Executive Branch (FCEB) agencies to secure vulnerable servers within three days. At the time of that addition, the agency warned, "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise." In follow-up guidance, CISA urged teams to monitor affected servers for signs of exploitation, apply Microsoft's latest patches, verify successful installation, and shorten patching cycles.

Ransomware abuse and related threats

In a Tuesday update to the KEV Catalog, CISA flagged CVE-2026-45659 specifically as being abused by ransomware gangs. The agency's update places this SharePoint flaw alongside a pattern CISA has tracked since November 2021: the agency has listed 14 actively exploited Microsoft SharePoint vulnerabilities in that span, and eight of those have been exploited in ransomware attacks. CISA has also recommended enabling Windows Antimalware Scan Interface (AMSI) integration for SharePoint web applications and using Microsoft Defender Antivirus (MDAV) detections to detect and remediate compromise.

Exposure snapshot: Shadowserver's counts

Internet security watchdog Shadowserver is currently tracking more than 8,500 Microsoft SharePoint servers exposed online. Of those, the group reports that over 200 remain unpatched against CVE-2026-45659. Microsoft has not updated its CVE-2026-45659 advisory to mark the issue as exploited, even as CISA and external observers report active exploitation.

What this means for security teams, FCEB agencies, and enterprises

  • Security teams: Monitor affected SharePoint instances for indicators of compromise, enable AMSI integration for SharePoint web applications, deploy Microsoft Defender Antivirus detections, apply Microsoft's May patches, and verify installations. CISA explicitly urged shortening patch cycles and active monitoring.
  • FCEB agencies: The KEV listing carried a three-day remediation order; affected federal agencies face a short window to secure servers and follow CISA's verification and detection recommendations to meet the directive.
  • Affected enterprises and procurement leaders: Shadowserver's count of over 8,500 exposed servers — with more than 200 unpatched to this specific CVE — underscores the gap between patch availability and deployment. Enterprises should prioritize the May SharePoint updates cited by Microsoft and align detection controls (AMSI and MDAV) as recommended by CISA.

CISA's announcement places an exploited SharePoint deserialization flaw squarely in the crosshairs of ransomware operators and federal defenders alike. Microsoft supplied fixes in May; CISA put the vulnerability on the KEV list on July 1 and escalated to a ransomware-abuse flag in a subsequent update. The named technical detail — that this is a low-complexity exploit where "an attacker does not require significant prior knowledge" — makes the choice stark: apply and verify the published patches, enable the recommended detection controls, or risk seeing servers become the next vector for ransomware campaigns.

Original story: https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-flaw-now-exploited-in-ransomware-attacks/