The Financial Register.

Inward fraud & financial crime, explained for Gen Z

Live coverage / The Wire

Update · 08:36 am AEST · 12 August 2026

40 DAYS AGO Key event Share

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
Photograph: BleepingComputer

The U.S. Cybersecurity and Infrastructure Security Agency confirmed Tuesday that ransomware gangs are exploiting CVE-2026-45659, a high-severity remote code execution vulnerability in Microsoft SharePoint that allows attackers with low privileges to execute arbitrary code on unpatched servers. CISA added the flaw to its Known Exploited Vulnerabilities Catalog on July 1 and ordered federal agencies to patch within three days.

Microsoft released fixes in May for SharePoint Enterprise Server 2016, SharePoint Server 2019 and SharePoint Server Subscription Edition. The vulnerability stems from a deserialization of untrusted data weakness and "does not require significant prior knowledge of the system", Microsoft said. Internet security firm Shadowserver is tracking over 8,500 exposed SharePoint servers online, with more than 200 remaining unpatched against the flaw.

CISA has now flagged 14 actively exploited Microsoft SharePoint vulnerabilities since November 2021, with eight also used in ransomware attacks, Sergiu Gatlan reports for BleepingComputer.

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. bleepingcomputer.com
cybersecurityransomwarevulnerabilitymicrosoftcisa

Follow the live coverage →

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks | The Financial Register Inward Money