Ransomware Exploits Critical SharePoint Vulnerability CVE-2026-45659

Ransomware Exploits Critical SharePoint Vulnerability CVE-2026-45659

First seen 12 Aug 2026, 02:41 UTC Feeds.4SysopsHeise.De 81% similarity 72.8

Article Content

Browse articles
ThreatCluster

CISA has confirmed that ransomware groups are actively exploiting a critical vulnerability (CVE-2026-45659) in Microsoft SharePoint Server, which allows remote code execution. Over 200 unpatched SharePoint servers are currently exposed on the internet, primarily in the USA and Europe. The vulnerability arises from the deserialization of untrusted data, enabling attackers to inject malicious code without needing elevated privileges. Microsoft released security updates for affected SharePoint versions in May 2026, but many organizations have not yet applied these patches. The urgency for remediation is heightened as the exploitation is confirmed to be in progress. Shadowserver Foundation's scans indicate a significant drop in unpatched instances since June, but risks remain. Organizations running on-premises SharePoint deployments are particularly at risk.

Key Points: • CVE-2026-45659 is actively exploited for ransomware attacks on SharePoint servers. • Over 200 unpatched SharePoint servers are exposed on the internet, mainly in the USA and Europe. • Microsoft released security updates in May 2026, but many organizations have not yet patched.

ThreatCluster AI How this analysis works

Timeline

2026-05-22
CVE-2026-45659 published
Microsoft disclosed a critical remote code execution vulnerability in SharePoint Server.
Heise.De
2026-05-27
First public PoC released
A proof of concept for CVE-2026-45659 was made publicly available, demonstrating the exploit.
Heise.De
2026-07-01
CVE added to CISA KEV
CISA confirmed active exploitation of CVE-2026-45659, urging immediate action.
Feeds.4Sysops
2026-08-11
CISA warns of ongoing ransomware attacks
CISA confirmed that ransomware groups are actively exploiting the SharePoint vulnerability.
Feeds.4Sysops
2026-08-11
Shadowserver scans reveal unpatched servers
Shadowserver identified over 200 internet-exposed SharePoint servers that remain unpatched.
Heise.De

Community

Browse all →