CISA Confirms SharePoint Flaw Used in Ransomware Attacks
The US cybersecurity agency CISA has confirmed a critical Microsoft SharePoint vulnerability is now actively exploited by ransomware gangs, placing unpatched servers at immediate risk.
What Happened
August 11, 2026 – The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that a critical vulnerability in Microsoft SharePoint, a widely used corporate software, is now being actively exploited by ransomware gangs. The agency announced this critical information through an update to its Known Exploited Vulnerabilities (KEV) Catalog, which lists vulnerabilities known to be actively exploited. This development sounds the alarm for thousands of organizations that manage SharePoint servers.
The vulnerability in question is tracked as CVE-2026-45659 and is classified as a high-severity remote code execution (RCE) flaw. Initially identified by CISA as actively exploited in early July, this flaw has now appeared on the radar of ransomware groups. The adoption of this vulnerability by ransomware actors could lead to far more devastating consequences than a simple system breach, including the encryption of an organization's entire data and a complete halt to operations. CISA's confirmation elevates the threat's severity and serves as an urgent call to action for system administrators. The agency had previously given federal agencies a tight three-day deadline in July to patch this flaw, further underscoring its significant danger.
What Data Was Compromised
There has been no detailed disclosure regarding the specific types of data compromised in these attacks. However, due to the nature of the attack, all data on an unpatched SharePoint server is potentially at risk. SharePoint is a central platform used by organizations to store sensitive documents, internal communications, project plans, financial reports, and personal data. Therefore, an attacker who infiltrates a server through this vulnerability could theoretically access all of this information.
Modern ransomware attacks often employ a "double extortion" tactic. In this strategy, attackers not only encrypt the data but also exfiltrate copies to their own servers. If the victim refuses to pay the ransom, the attackers threaten to make the data public or sell it on the dark web. Consequently, an organization targeted via the CVE-2026-45659 vulnerability faces not only an operational shutdown but also the severe risk of a data breach and reputational damage. You can use our Data Breach Search tool to find out if your organization's data has been compromised.
How Did the Attack Happen
The technical basis of the attack lies in the security vulnerability coded as CVE-2026-45659. This flaw stems from a weakness known as "deserialization of untrusted data." In simple terms, the SharePoint server fails to perform adequate security checks when processing a specially crafted, malicious data packet from an external source. This allows an attacker to execute arbitrary code remotely on the server.
According to a security bulletin released by Microsoft in May, an attacker does not need high privileges to execute this attack; a low-privileged account is sufficient. Furthermore, the attack complexity is rated as "low." This means an attacker can easily and repeatedly launch successful attacks with a known exploit code without needing in-depth knowledge of the target system. These characteristics make CVE-2026-45659 a very attractive target for cybercriminals, especially ransomware groups. For information on other cybersecurity incidents, you can follow our Data Breach News page.
Who Is Affected
All institutions and organizations using the following versions of Microsoft SharePoint are directly affected by this vulnerability:
- SharePoint Enterprise Server 2016
- SharePoint Server 2019
- SharePoint Server Subscription Edition
According to data shared by the internet security watchdog group Shadowserver, there are currently over 8,500 internet-exposed Microsoft SharePoint servers. More alarmingly, over 200 of these servers remain unpatched against the CVE-2026-45659 vulnerability. These servers are prime targets for ransomware gangs. However, the risk is not limited to internet-facing servers. Unpatched servers within an internal network can also serve as a valuable stepping stone for an attacker who has already breached the network through other means.
What Can You Do
CISA recommends a series of concrete steps for organizations to protect themselves against this serious threat. It is critical for system administrators and security teams to take the following measures without delay:
- Patch Immediately: The most fundamental and crucial step is to immediately apply the security updates released by Microsoft for this vulnerability in May 2026 to all affected SharePoint servers.
- Verify Installation: After deploying the patch, ensure that the update was successfully applied and that the server is no longer vulnerable.
- Monitor for Signs of Exploitation: Check your servers for any signs of past or present compromise. Carefully examine system logs, suspicious network traffic, and unexpected processes.
- Shorten Patching Cycles: CISA advises organizations to adopt a habit of applying patches more quickly in general, meaning they should shorten their patching cycles.
- Enable Additional Security Layers: CISA specifically recommends enabling Windows Antimalware Scan Interface (AMSI) integration for SharePoint web applications. Additionally, keeping security software like Microsoft Defender Antivirus (MDAV) updated with the latest detection signatures can help detect and block a potential attack.
What Is the Company Saying
As of the writing of this report, an interesting situation has emerged. While CISA has officially confirmed that the CVE-2026-45659 vulnerability is both actively exploited and used in ransomware attacks, the software's developer, Microsoft, has not yet updated its own security advisory to reflect this. Microsoft's page does not have a tag indicating the vulnerability is being exploited. This situation shows that government agencies can sometimes confirm threat intelligence faster than the companies themselves.
A similar scenario occurred with the BlueHammer (CVE-2026-33825) Microsoft Defender privilege escalation vulnerability, which CISA confirmed in June was being used by ransomware groups. For that vulnerability as well, Microsoft did not make a public confirmation of exploitation despite CISA's warning. This once again highlights the importance for organizations to closely follow warnings not only from software vendors but also from trusted government agencies like CISA.
Source
This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.