The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a high-severity vulnerability in Microsoft SharePoint that is currently being exploited by ransomware gangs. This critical issue, tracked as CVE-2026-45659, stems from a deserialization of untrusted data weakness, allowing low-privileged attackers to execute arbitrary code on unpatched SharePoint servers. The vulnerability has been flagged as actively exploited since early July 2026.
Understanding the Vulnerability
CVE-2026-45659 represents a significant security risk for organizations using Microsoft SharePoint, particularly because it can be exploited in low-complexity attacks. Microsoft indicated that an attacker does not need substantial prior knowledge of the system to leverage this vulnerability successfully. This ease of exploitation makes it a frequent target for malicious actors.
The vulnerability can lead to severe consequences, including unauthorized access to sensitive data and system control, making it a prime attack vector for ransomware attacks.
CISA’s Action and Recommendations
On July 1, CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog (KEV), mandating that Federal Civilian Executive Branch (FCEB) agencies secure their servers within three days. In its advisory, CISA emphasized the urgency of patching unprotected systems, urging security teams to closely monitor for signs of exploitation.
- Apply Microsoft’s latest security updates promptly.
- Verify successful installation of patches.
- Implement shorter patching cycles to mitigate risks.
- Enable Windows Antimalware Scan Interface (AMSI) integration for SharePoint web applications.
- Utilize Microsoft Defender Antivirus (MDAV) for monitoring and remediation.
Status of Affected Systems
According to Internet security watchdog group Shadowserver, over 8,500 Microsoft SharePoint servers are currently exposed online, with more than 200 of these servers remaining unpatched against the CVE-2026-45659 vulnerability. This alarming statistic highlights the urgent need for organizations to assess and secure their SharePoint environments.
Despite the critical nature of this vulnerability, Microsoft has yet to update its advisory to recognize CVE-2026-45659 as actively exploited in the wild. However, CISA’s confirmation signals the importance of addressing the issue immediately.
Historic Exploits and Current Landscape
This is not the first instance of Microsoft SharePoint vulnerabilities being flagged by CISA. Since November 2021, the agency has identified 14 actively exploited SharePoint vulnerabilities, eight of which have been linked to ransomware attacks. This trend underscores the importance of ongoing vigilance in cybersecurity practices.
Additionally, earlier this year, a separate high-severity vulnerability in Microsoft Defender, known as BlueHammer, was also confirmed by CISA as a target for ransomware gangs. This exploit centered on privilege escalation and presented a severe risk to systems utilizing the Security Account Manager (SAM) database.
What’s Next for Organizations?
Organizations using Microsoft SharePoint must take immediate action to ensure proper security measures are in place. Key steps include:
- Performing routine audits of SharePoint installations.
- Implementing robust cybersecurity training for staff to recognize phishing attempts.
- Establishing incident response plans to address potential breaches effectively.
By prioritizing security and committing to regular updates, organizations can mitigate the risk associated with this and future vulnerabilities. The evolving landscape of cyber threats necessitates a proactive approach in safeguarding critical systems from potential exploitation.
For more details, please visit the official CISA advisory and Microsoft’s security updates.
