Heise.De
Ransomware Exploits Critical SharePoint Vulnerability CVE-2026-45659
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
CISA has confirmed that ransomware groups are actively exploiting a critical vulnerability (CVE-2026-45659) in Microsoft SharePoint Server, which allows remote code execution. Over 200 unpatched SharePoint servers are currently exposed on the internet, primarily in the USA and Europe. The vulnerability arises from the deserialization of untrusted data, enabling attackers to inject malicious code without needing elevated privileges. Microsoft released security updates for affected SharePoint versions in May 2026, but many organizations have not yet applied these patches. The urgency for remediation is heightened as the exploitation is confirmed to be in progress. Shadowserver Foundation's scans indicate a significant drop in unpatched instances since June, but risks remain. Organizations running on-premises SharePoint deployments are particularly at risk.
Key Points: • CVE-2026-45659 is actively exploited for ransomware attacks on SharePoint servers. • Over 200 unpatched SharePoint servers are exposed on the internet, mainly in the USA and Europe. • Microsoft released security updates in May 2026, but many organizations have not yet patched.