Skip to content
Ransomware attacks unpatched SharePoint instances

Ransomware attacks unpatched SharePoint instances

Heise.De • August 12, 2026

Administrators running Microsoft SharePoint Server in their infrastructure should check if they have installed the May updates. This is because the highly critical SharePoint vulnerability CVE-2026-45659 (CVSS 8.8, risk “high”), which allows attackers to inject and execute malicious code, is now actively being exploited for ransomware campaigns.

This is according to an update in the Known Exploited Vulnerabilities Catalogue of the US agency CISA (Cybersecurity & Infrastructure Security Agency) from Tuesday. Further details the breaches are not yet available to heise security. Microsoft has not yet confirmed the active exploitation in the wild. The SharePoint provider released corresponding security updates for SharePoint Enterprise Server 2016 (which also applies to SharePoint Server 2016), SharePoint Server 2019, and the Server Subscription Edition at the end of May.

However, scans by the Shadowserver Foundation on Monday found more than 200 IP addresses from which unpatched SharePoint servers accessible via the internet could be reached. half of these are assigned to the USA, and a quarter to Europe. For Germany, the statistics currently show around a dozen such unsecured SharePoint servers, and low single-digit numbers for Austria and Switzerland. There could be additional cases that were not found or recognized during the scans. At the beginning of June, Shadowserver still saw a good 1,100 unpatched SharePoint instances online.

The security problem arises from the deserialization of untrusted data, meaning its unpacking and processing up to its execution. Deserialization is defined as the process by which a program reads data from a sequential representation (e.g., a text or binary file) and converts it into objects with which it can interact; the data then exists in a random-access memory format, such as RAM. Attackers logged into an unpatched SharePoint can inject software code over the network. No elevated privileges are required for this, and the attack works even from the internet.

Since attackers do not need detailed knowledge of vulnerable systems beforehand to attack them successfully, such an attack is considered not very complex. Nevertheless, Microsoft estimated in May that the abuse of this vulnerability was less likely ( “Exploitation less likely” ). The CVSS Temporal Score was determined to be 7.7 at the time.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.