CVE Tools

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

BleepingComputerBy Sergiu Gatlan

Reported exploitedSharePoint ServerDefender Antivirus

Our summary

CISA has confirmed that ransomware campaigns are actively leveraging a high-severity remote code execution vulnerability in Microsoft SharePoint, identified as CVE-2026-45659. This flaw, which stems from improper handling of untrusted data, enables low-privilege attackers to execute arbitrary code on SharePoint Server 2016, 2019, and Subscription Edition instances with minimal effort. Although the vulnerability was added to the Known Exploited Vulnerabilities catalog in early July, recent updates indicate its specific use in ransomware operations.

Administrators are urged to verify that Microsoft’s latest security patches are installed and to monitor for signs of compromise using Microsoft Defender Antivirus detections.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store