CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
Reported exploitedSharePoint ServerDefender AntivirusOur summary
CISA has confirmed that ransomware campaigns are actively leveraging a high-severity remote code execution vulnerability in Microsoft SharePoint, identified as CVE-2026-45659. This flaw, which stems from improper handling of untrusted data, enables low-privilege attackers to execute arbitrary code on SharePoint Server 2016, 2019, and Subscription Edition instances with minimal effort. Although the vulnerability was added to the Known Exploited Vulnerabilities catalog in early July, recent updates indicate its specific use in ransomware operations.
Administrators are urged to verify that Microsoft’s latest security patches are installed and to monitor for signs of compromise using Microsoft Defender Antivirus detections.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.