Breaking
SecurityConfirmed

CISA Ties SharePoint Flaw to Ransomware

CISA adds CVE-2026-45659 to KEV catalog, confirming ransomware abuse of a Microsoft SharePoint RCE flaw.

··2 hours ago·3 min read
padlock on laptop with light trails
Photo by FlyD on Unsplash

U.S. cybersecurity officials have confirmed that ransomware gangs are now abusing a high-severity Microsoft SharePoint remote code execution vulnerability, a development that escalates the threat for thousands of exposed servers. The flaw, tracked as CVE-2026-45659, has been on the radar since early July, but Tuesday's update to CISA's Known Exploited Vulnerabilities catalog marks a formal acknowledgment of its use in ransomware campaigns.

A Deserialization Flaw

The vulnerability stems from a deserialization of untrusted data weakness, allowing attackers with low privileges to execute arbitrary code on unpatched SharePoint servers. Microsoft explained in May, when it released security updates for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition, that "an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component."

Added to CISA's KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities Catalog on July 1, ordering Federal Civilian Executive Branch agencies to secure their servers within three days. "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," the agency warned at the time.

Subsequent Advisory Urges Monitoring

In a subsequent advisory, CISA also urged security teams to monitor affected servers for signs of exploitation, apply Microsoft's latest patches, verify successful installation, and shorten patching cycles. The agency recommended enabling Windows Antimalware Scan Interface (AMSI) integration for SharePoint web applications and using Microsoft Defender Antivirus (MDAV) detections to detect and remediate compromise.

Thousands of Exposed Servers

Internet security watchdog group Shadowserver currently tracks over 8,500 Microsoft SharePoint servers exposed online, with over 200 of them unpatched against the CVE-2026-45659 vulnerability.

Ransomware Confirmation

While Microsoft has yet to update the CVE-2026-45659 advisory to tag it as exploited, CISA has now flagged it as abused by ransomware gangs in Tuesday's update to the KEV Catalog. This marks a notable escalation in the threat landscape, as the flaw was previously only known to be actively exploited in general.

A Pattern of SharePoint Exploitation

Since November 2021, CISA has flagged 14 actively exploited Microsoft SharePoint vulnerabilities, with eight of them also exploited in ransomware attacks. This latest addition continues a pattern of SharePoint being a prime target for cybercriminals.

Related Defender Flaw

In June, CISA also confirmed that ransomware gangs now exploit a high-severity Microsoft Defender privilege escalation vulnerability, dubbed BlueHammer, which was also targeted as a zero-day to access the Security Account Manager (SAM) database, which contains password hashes for local accounts. The security flaw, tracked as CVE-2026-33825, was leaked by a security researcher known as "Nightmare Eclipse" in early April, together with proof-of-concept exploit code. As with CVE-2026-45659, Microsoft has yet to confirm that this flaw is being exploited in the wild.

Why It Matters

For organizations running SharePoint, the confirmation of ransomware abuse raises the stakes significantly. The vulnerability allows low-privilege attackers to execute arbitrary code, making it a viable entry point for ransomware campaigns that could encrypt critical files and disrupt operations. With over 8,500 servers exposed online and more than 200 still unpatched, the attack surface is real. The pattern of 14 SharePoint flaws exploited since 2021, with eight used in ransomware attacks, suggests that this platform will continue to be a focus for cybercriminals. The window for patching without incident may be closing, and every day of delay increases the likelihood that an unpatched server becomes a victim.

#cve-2026-45659#sharepoint#ransomware#cisa#microsoft

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted through our automated editorial pipeline from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our Automation Policy →

← Back to all stories