Heise.De Ransomware Exploits Critical SharePoint Vulnerability CVE-2026-45659
Article Content
- •CVE-2026-45659 is actively exploited for ransomware attacks on SharePoint servers.
- •Over 200 unpatched SharePoint servers are exposed on the internet, mainly in the USA and Europe.
- •Microsoft released security updates in May 2026, but many organizations have not yet patched.
CISA has confirmed that ransomware groups are actively exploiting a critical vulnerability (CVE-2026-45659) in Microsoft SharePoint Server, which allows remote code execution. Over 200 unpatched SharePoint servers are currently exposed on the internet, primarily in the USA and Europe. The vulnerability arises from the deserialization of untrusted data, enabling attackers to inject malicious code without needing elevated privileges. Microsoft released security updates for affected SharePoint versions in May 2026, but many organizations have not yet applied these patches. The urgency for remediation is heightened as the exploitation is confirmed to be in progress. Shadowserver Foundation's scans indicate a significant drop in unpatched instances since June, but risks remain. Organizations running on-premises SharePoint deployments are particularly at risk.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track CVE-2026-45659 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical SharePoint RCE Vulnerabilities Exploited in the Wild CVE-2026-45659 and CVE-2026-58644 are critical remote code execution (RCE) vulnerabilities affecting Microsoft SharePoint Server. CVE-2026-45659, published on May 22, 2026, allows authenticated users to exploit deserialization flaws for RCE under the IIS application pool identity. CVE-2026-58644, discovered in July…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…