CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

By Sergiu Gatlan
Publication Date: 2026-08-11 12:12:00

CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July.

Tracked as CVE-2026-45659, this security flaw stems from a deserialization of untrusted data weakness and allows attackers with low privileges to execute arbitrary code on unpatched SharePoint servers.

It can also be exploited in low-complexity attacks because (as Microsoft explained in May when it released security updates for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition) “an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.”

image

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities Catalog (KEV) on July 1, ordering Federal Civilian…