Originally published at https://tekmag.thsite.top/cisa-microsoft-sharepoint-flaw-cve-2026-45659-now-actively-exploited-by-ransomware-gangs/
CISA: Microsoft SharePoint Flaw CVE-2026-45659 Now Actively Exploited by Ransomware Gangs
CVE-2026-45659 is a deserialization vulnerability in Microsoft SharePoint that allows unauthenticated remote code execution at low privilege levels.
According to BleepingComputer, CISA updated its Known Exploited Vulnerabilities catalog on August 11, 2026, to reflect active ransomware exploitation of the flaw. The vulnerability affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition, with a CVSS 3.1 score of 8.8.
Key Takeaways
- CVE-2026-45659 enables remote code execution without admin rights or user interaction.
- CISA added the flaw to its KEV catalog on July 1, 2026, and updated it for ransomware activity on August 11.
- Microsoft released patches on May 21, 2026, but hundreds of servers remain unpatched.
- Exploitation requires only Site Member permissions and no user interaction.
- Shadowserver reports thousands of internet-exposed SharePoint servers globally.
What Is CVE-2026-45659?
CVE-2026-45659 is a critical deserialization-of-untrusted-data vulnerability in Microsoft SharePoint that enables network-based remote code execution. The flaw affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition, according to the National Vulnerability Database entry.
The vulnerability carries a CVSS 3.1 score of 8.8 high, with the vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. Attackers can exploit it over the network with low attack complexity, requiring only low-privilege permissions and no user interaction to achieve full confidentiality, integrity, and availability impacts.
How Ransomware Gangs Are Exploiting It
According to BleepingComputer's reporting on CISA's August 11 update, ransomware groups are actively abusing CVE-2026-45659 to gain initial access to SharePoint environments. The group names remain unconfirmed in primary sources, but the campaign pattern matches known ransomware tradecraft: exploiting internet-facing servers, establishing persistence, and encrypting data for extortion.
Successful exploitation does not require administrative rights. Attackers need only Site Member-level permissions and no user interaction, making it trivially easy to compromise exposed SharePoint installations. According to CISA's original KEV listing, federal agencies were ordered to secure affected servers within three days of the July 1 announcement.
Who Is Affected and How Widespread Is the Exposure?
Microsoft published security updates for all affected SharePoint versions on May 21, 2026, according to the official Microsoft security update guide. However, Shadowserver researchers report that thousands of SharePoint servers remain exposed to the internet, with hundreds still running unpatched against CVE-2026-45659.
The low-privilege remote code execution combined with widespread internet exposure creates a high-risk environment for organizations with remote workers and hybrid IT setups. The vulnerability was added to CISA's KEV catalog on July 1, 2026, nearly two months after the initial patch release, suggesting a significant gap between patch availability and organizational remediation.
Detection and Mitigation Steps
Administrators should verify that all SharePoint servers have received the May 21, 2026 security updates. Organizations can check patch status through the Microsoft Security Update Guide and run vulnerability scanning tools against internet-facing SharePoint endpoints.
Additional hardening measures include enabling AMSI (Antimalware Scan Interface) on SharePoint servers, monitoring web-request telemetry for suspicious deserialization patterns, and shortening patching cycles for internet-exposed systems. Defender Antivirus can detect exploitation attempts, and administrators should review logs for anomalous SharePoint requests from unexpected IP ranges.
Why This Matters for Enterprise Security
CVE-2026-45659 represents a rare combination of high severity, low exploitation barriers, and active ransomware campaigns. The vulnerability's CVSS score of 8.8 places it in the critical tier, while the fact that it requires only Site Member permissions and no user interaction makes it accessible to threat actors with minimal technical expertise.
Organizations relying on SharePoint for document management, collaboration, or hybrid work infrastructure should treat this as a priority. The delayed patch adoption cycle, combined with the ransomware-campaign escalation documented by CISA, creates a window of extended risk for unpatched environments.
For teams managing Microsoft 365 deployments, our guide to Microsoft 365 security hardening covers additional protections for SharePoint Online and on-premises environments. Organizations seeking to understand broader threat trends can review our ransomware prevention checklist for enterprise IT teams.
Conclusion
CVE-2026-45659 remains a critical threat to Microsoft SharePoint environments worldwide, with active ransomware exploitation confirmed by CISA and thousands of unpatched servers still exposed. Immediate patching and hardening measures are essential to mitigate risk.
FAQ
Q: What is CVE-2026-45659?
A: CVE-2026-45659 is a deserialization vulnerability in Microsoft SharePoint that allows unauthenticated remote code execution. It affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition, with a CVSS score of 8.8.
Q: Who can exploit CVE-2026-45659?
A: Attackers with Site Member-level permissions can exploit CVE-2026-45659 without requiring administrative rights or user interaction. This low barrier to exploitation has made it attractive to ransomware groups.
Q: When did CISA add CVE-2026-45659 to the KEV catalog?
A: CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog on July 1, 2026, and updated the entry on August 11, 2026, to reflect active ransomware campaign exploitation.
Q: How many SharePoint servers remain unpatched?
A: According to Shadowserver, thousands of internet-exposed SharePoint servers exist globally, with hundreds still running unpatched versions vulnerable to CVE-2026-45659 as of August 2026.
Q: What should administrators do to protect their SharePoint environments?
A: Administrators should apply the May 21, 2026 Microsoft security updates immediately, enable AMSI, monitor web-request telemetry for suspicious deserialization patterns, and restrict internet exposure for SharePoint servers where possible.
Top comments (0)