The U.S. Cybersecurity and Infrastructure Security Agency has confirmed that ransomware groups are now abusing a serious vulnerability in Microsoft SharePoint Server. The flaw is tracked as CVE-2026-45659 and allows remote code execution through a deserialization weakness. It has been under active exploitation since early July, raising the risk for vulnerable on-premises SharePoint systems. Security teams are being urged to treat the vulnerability as an active attack risk rather than a routine patching issue.

sharepoint-server-vulnerability

CVE-2026-45659 carries a CVSS score of 8.8 and affects SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. The vulnerability can be abused by an authenticated attacker with low-level privileges to execute arbitrary code over the network. Microsoft describes the attack as relatively low complexity, meaning attackers do not need extensive knowledge of the target environment to achieve repeatable results. This makes exposed and unpatched SharePoint servers particularly attractive targets.

Microsoft released an out-of-band security update for the vulnerability in May 2026 after the issue was identified in SharePoint. The affected products include SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition, with specific fixed build versions provided by Microsoft. CISA later added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog on July 1. Federal civilian agencies were given a very short deadline to secure affected systems because exploitation was already taking place.

sharepoint-cybersecurity-attack

The latest warning is especially important because CISA has now identified ransomware use of the SharePoint vulnerability. This means attackers are not only testing or exploiting the flaw, but it has become part of attacks that can lead to ransomware activity. CISA says the vulnerability has been used by malicious actors and warns that this class of weakness represents a significant risk to enterprise environments. The agency has also urged organizations to watch their SharePoint servers for signs of compromise.

The risk is increased by the number of SharePoint systems still visible on the internet. Security monitoring organization Shadowserver was tracking more than 8,500 internet-exposed Microsoft SharePoint servers, including more than 200 that remained unpatched against CVE-2026-45659. An internet-facing server that has not received the required security update can give attackers an easier path into an organization. Once access is obtained, attackers may attempt further actions inside the network and potentially move toward ransomware deployment.

ransomware-attack-sharepoint

CISA recommends that security teams apply Microsoft’s latest SharePoint security updates and confirm that the patches were installed successfully. Organizations should monitor affected servers for unusual activity and investigate any indicators that could suggest exploitation. The agency recommends enabling Antimalware Scan Interface integration for SharePoint web applications and using Microsoft Defender Antivirus detections to help identify and respond to malicious activity. These steps can improve visibility while organizations work to close the exposure.

The warning also shows why patching internet-facing enterprise software cannot be treated as a normal maintenance task. SharePoint often stores or provides access to important business documents and information, so a compromised server can become a valuable target for attackers. CISA has already identified multiple SharePoint vulnerabilities as actively exploited since 2021, with several also linked to ransomware campaigns. The continued targeting of SharePoint shows that attackers are closely watching widely deployed enterprise platforms.

sharepoint-cve-2026-45659

For organizations using on-premises SharePoint, the priority is to verify affected servers, apply Microsoft’s security updates, and check whether any vulnerable systems were exposed during the exploitation period. Teams should review logs for suspicious activity and investigate systems that show unexpected behavior. Because CISA has now confirmed ransomware exploitation, delaying remediation creates a serious security risk today. The situation is a reminder that a patch is only effective when organizations install and verify it.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news