CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

The U.S. Cybersecurity and Infrastructure Security Agency confirmed Tuesday that ransomware gangs are exploiting CVE-2026-45659, a high-severity remote code execution vulnerability in Microsoft SharePoint that allows attackers with low privileges to execute arbitrary code on unpatched servers. CISA added the flaw to its Known Exploited Vulnerabilities Catalog on July 1 and ordered federal agencies to patch within three days.
Microsoft released fixes in May for SharePoint Enterprise Server 2016, SharePoint Server 2019 and SharePoint Server Subscription Edition. The vulnerability stems from a deserialization of untrusted data weakness and "does not require significant prior knowledge of the system", Microsoft said. Internet security firm Shadowserver is tracking over 8,500 exposed SharePoint servers online, with more than 200 remaining unpatched against the flaw.
CISA has now flagged 14 actively exploited Microsoft SharePoint vulnerabilities since November 2021, with eight also used in ransomware attacks, Sergiu Gatlan reports for BleepingComputer.