Illustrative image generated with AI
SharePoint: CISA Confirms Ransomware Exploitation of CVE-2026-45659
CISA confirms ransomware exploitation of SharePoint CVE-2026-45659 vulnerability. Patch servers and enable AMSI to prevent code execution and network breaches.
Text generated by artificial intelligence, published without human review. AI transparency
Exposed SharePoint Servers Targeted
On August 11, 2026, CISA confirmed that ransomware groups are actively exploiting CVE-2026-45659, a Microsoft SharePoint vulnerability.
The flaw had already been added to the Known Exploited Vulnerabilities (KEV) catalog on July 1. CISA subsequently ordered U.S. federal civilian agencies to secure their servers within three days.
A later catalog update clarified that the vulnerability is also being used by ransomware gangs. Microsoft, however, has not yet updated the CVE-2026-45659 advisory to reflect the ongoing exploitation.
According to Shadowserver, more than 8,500 Microsoft SharePoint servers are exposed online. Over 200 reportedly remain unprotected against this vulnerability.
Deserialization Flaw Leads to Code Execution
CVE-2026-45659 is a high-severity flaw involving the deserialization of untrusted data. An attacker with low-level privileges can exploit it to remotely execute arbitrary code on an unpatched SharePoint server.
The attack has low complexity: it does not require extensive knowledge of the target environment, and the payload can produce repeatable results on the vulnerable component.
The operational risk extends beyond the individual SharePoint service. An initial compromise can provide threat actors with an entry point to move laterally across the network, steal data, and deploy ransomware.
Affected Products and Campaign Context
The affected products are:
- Microsoft SharePoint Enterprise Server 2016;
- Microsoft SharePoint Server 2019;
- Microsoft SharePoint Server Subscription Edition.
Microsoft Defender Antivirus (MDAV) and the Windows Antimalware Scan Interface (AMSI) are also involved in protection and detection efforts.
Since November 2021, CISA has reported 14 Microsoft SharePoint vulnerabilities being actively exploited. Eight of them have also been used in ransomware attacks.
In June, CISA also confirmed the ransomware exploitation of CVE-2026-33825, a high-severity privilege escalation flaw in Microsoft Defender known as BlueHammer. Microsoft has not confirmed in-the-wild exploitation of either that vulnerability or, so far, CVE-2026-45659.
What Administrators Should Do
Organizations managing SharePoint should:
- apply the latest Microsoft patches to the affected products;
- verify that the updates were installed successfully;
- prioritize servers directly exposed to the Internet;
- enable AMSI integration for SharePoint web applications;
- use Microsoft Defender Antivirus detections to look for signs of compromise;
- check systems for indicators of exploitation;
- shorten patch deployment cycles.
The exact vulnerable build versions and specific technical indicators of intrusion have not been disclosed. Until further details become available, the most urgent measures are to update exposed SharePoint servers and then review logs and active security controls.
Sources
This article is an original reworking based on the sources below.
