Full research report
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
Executive assessment
CVE-2026-45659 is an important-severity SharePoint Server vulnerability in which unsafe deserialisation can give a low-privileged authenticated attacker remote code execution. Microsoft's affected-product data confirms three supported on-premises SharePoint lines and identifies the May 2026 fixed builds. CISA's later evidence supersedes Microsoft's unchanged exploitation flag for operational prioritisation: the flaw is in KEV and is explicitly marked as known in ransomware campaigns. The public records reviewed do not reveal which ransomware operation used it, against whom, or whether reusable exploit code is publicly available.
What happened
Microsoft published CVE-2026-45659 on 21 May 2026 for a SharePoint Server remote-code-execution vulnerability already addressed by May security updates. CISA added it to the Known Exploited Vulnerabilities catalogue on 1 July after finding evidence of active exploitation and subsequently marked it as known to be used in ransomware campaigns. The separately supplied CVE-2026-33825 concerns Microsoft Defender and is contextual reporting, not the SharePoint event investigated here.
Affected scope
Microsoft identifies SharePoint Enterprise Server 2016, SharePoint Server 2019 and SharePoint Server Subscription Edition as affected. The vulnerability is remotely reachable over a network but requires an authenticated account with at least Site Member permissions; exposed and unpatched on-premises servers are therefore the priority.
Technical assessment
CVE-2026-45659 is a CWE-502 deserialisation-of-untrusted-data weakness. A low-privileged authenticated attacker can cause a vulnerable SharePoint server to process unsafe data and execute code remotely, with potential loss of confidentiality, integrity and availability. CISA confirms exploitation and ransomware association, but the reviewed public evidence does not identify a ransomware family, actor, victim or public exploit implementation.
Recommended defensive actions
- Apply the relevant May 2026 or later SharePoint security update to every affected farm and confirm all servers meet or exceed the fixed build.
- Inventory internet-exposed SharePoint Server deployments and restrict external access wherever it is not operationally required.
- Audit Site Member and other authenticated SharePoint accounts, revoke unnecessary access and investigate anomalous or recently created accounts.
- Hunt for suspicious authenticated SharePoint requests, unexpected child processes, newly written executable or script content, and persistence introduced before patching.
- Verify successful update installation across every SharePoint server rather than relying solely on central deployment status.
Uncertainties and evidence gaps
- CISA does not publicly identify the ransomware group, malware family, victims or incident count behind the ransomware designation.
- Microsoft's record still states that exploitation is not confirmed, contradicting CISA's later assessment; CISA is stronger for current exploitation status because its KEV entry explicitly rests on exploitation evidence and records ransomware use.
- No public proof-of-concept or independently verified exploit code for CVE-2026-45659 was found in the reviewed sources.
- The supplied claim that more than 200 exposed servers remained unpatched could not be verified from a working Shadowserver source page.
Vulnerability flow
Defender-oriented path reconstructed only from sourced report findings. Unknown stages are omitted.
Confirmed active exploitation; CISA marks CVE-2026-45659 as known to be used in ransomware campaigns, but no public proof-of-concept was verified.
The investigation separated the current SharePoint ransomware story from contextual reporting about CVE-2026-33825. Microsoft and NVD established the affected products, authenticated attack prerequisite and deserialisation mechanism, while CISA supplied the stronger evidence that exploitation is occurring and is associated with ransomware. No verified public proof-of-concept, named actor, malware family or victim reporting was found, so attribution remains open.
- Did the supplied article provide independently reviewable evidence for the headline?Opened the supplied BleepingComputer URL.bleepingcomputer.com โ
The site returned an automated security-verification page rather than accessible article content.
why The article could not serve as a verified citation, so the assessment had to rely on accessible primary records.
- What weakness and exploitation status do government vulnerability records assign to CVE-2026-45659?Read the NVD vulnerability record.nvd.nist.gov โ
NVD describes authenticated network code execution through deserialisation of untrusted data, assigns Microsoft's CVSS 3.1 score of 8.8 and identifies the CVE as present in CISA KEV.
why This corroborated the technical mechanism and established that the event concerns a real SharePoint vulnerability rather than CVE-2026-33825.
- What does Microsoft say about prerequisites, disclosure and remediation timing?Read Microsoft's structured vulnerability advisory.api.msrc.microsoft.com โ
Microsoft says an authenticated attacker with Site Member permissions can execute code over a network and that May 2026 updates addressed the vulnerability; its record still labels exploitation as unconfirmed.
why This established the access requirement and patch timing while exposing a material status discrepancy with CISA.
- Does CISA explicitly confirm exploitation and ransomware use?Filtered and read CISA's KEV catalogue entry for the CVE.cisa.gov โ
CISA lists CVE-2026-45659 as known exploited, marks ransomware use as known, and records addition on 1 July 2026 with remediation due by 4 July.
why CISA provides the decisive evidence for both current exploitation and the ransomware association.
- Was the KEV addition itself based on active-exploitation evidence?Read CISA's 1 July alert.cisa.gov โ
CISA states that it added CVE-2026-45659 based on evidence of active exploitation and urges prioritised remediation.
why This independently confirms the basis of the KEV designation, although it does not disclose incidents or actors.
- Exactly which products and fixed builds are documented?Queried Microsoft's affected-product record.api.msrc.microsoft.com โ
Microsoft lists SharePoint Enterprise Server 2016, SharePoint Server 2019 and Subscription Edition, with fixed builds 16.0.5552.1002, 16.0.10417.20128 and 16.0.19725.20280 respectively.
why This resolved the affected scope and enabled specific, verifiable patch guidance.
- Could the reported exposure count be independently verified?Opened the apparent Shadowserver vulnerable-SharePoint reporting page.shadowserver.org โ
The URL returned a 404 page and supplied no exposure data.
why The claimed count of exposed and unpatched servers was excluded from confirmed findings and retained as an evidence gap.
Research coverage
All 68 registered source leaves were evaluated for this run: 61 completed, 0 were unavailable, 0 failed and 7 were disabled. For this story, 6 registered sources supplied useful evidence (4 primary, 1 corroborating, 1 contextual and 0 PoC/exploit references). 55 completed sources contained no matched information for this story.
Complete source-by-source audit 68 sources
| Source | Run result | Value | Why it was useful โ or not |
|---|---|---|---|
| BleepingComputernews | ok15 records | Primary evidence1 matched items | Published the source report used to frame and date the event. |
| CISA KEVkev | ok1665 records | Primary evidence4 matched items | Confirmed that a related CVE is listed in CISA's Known Exploited Vulnerabilities catalogue. Supplied a vendor or government advisory opened and verified during focused research. |
| Microsoft MSRCvendor_advisory | ok1590 records | Primary evidence1 matched items | Supplied a vendor or government advisory opened and verified during focused research. |
| NVDcve | ok900 records | Primary evidence1 matched items | Supplied a vendor or government advisory opened and verified during focused research. |
| CISA Alertsnews | ok empty0 records | Corroborating1 matched items | A page from this source was opened and verified during focused research. |
| FIRST EPSSepss | ok | Context2 matched items | Added exploitation-probability context; EPSS does not itself prove exploitation. |
| AlienVault OTXdark_web | ok10 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| CIRCL CVEcve | ok30 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Cisco PSIRTvendor_advisory | ok5323 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Cisco Talosnews | ok1 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI CVE most exploiteddeepdarkcti | ok94 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Discorddeepdarkcti | ok7 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI exploitsdeepdarkcti | ok24 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI forumsdeepdarkcti | ok264 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI malware as a servicedeepdarkcti | ok7 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI malware samplesdeepdarkcti | ok3 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI marketsdeepdarkcti | ok127 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI phishingdeepdarkcti | ok19 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI ransomware gangsdeepdarkcti | ok680 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI RATsdeepdarkcti | ok1 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Telegram infostealerdeepdarkcti | ok130 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Telegram threat actorsdeepdarkcti | ok1008 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Twitter threat actorsdeepdarkcti | ok39 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| DNSDumpster domain IOC enrichmentresearch | ok1 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Exploit-DBexploit_reference | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Fortinet PSIRTvendor_advisory | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| GitHub topic: cveresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| GitHub topic: exploitresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| GitHub topic: penetration-testingresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| GitHub topic: pocresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| GitHub topic: vulnerabilityresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| GreyNoiseexploit_reference | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| KrebsOnSecuritynews | ok1 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| LinkedIn RSS proxy feeds (disabled)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| MalwareBazaardark_web | ok10 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #cveresearch | ok20 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #cybersecurityresearch | ok12 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #exploitresearch | ok20 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #infosecresearch | ok20 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #malwareresearch | ok20 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #ransomwareresearch | ok20 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #threatintelresearch | ok14 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Mastodon #vulnerabilityresearch | ok20 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Metasploit module metadataexploit_reference | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Microsoft Securitynews | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| MISP Galaxyresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| MISP threat actor galaxyactor | ok0 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Palo Alto Networks PSIRTvendor_advisory | ok25 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| ProjectDiscovery nuclei templatesexploit_reference | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Rapid7news | ok3 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Reddit r/AskNetsec (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/cybersecurity (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/malware (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/netsec (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/ReverseEngineering (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| SANS ISCnews | ok1 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Shadowserver public aggregate honeypot observationsexploit_reference | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Shodanresearch | ok7 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Sigma Rulesresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| Sophos IOCsresearch | ok1 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| The Hacker Newsnews | ok15 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| ThreatFoxthreat_intelligence | ok100 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| UK NCSCnews | ok1 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Unit42 IOCsresearch | ok empty0 records | Checked โ no match | The source completed but returned no records in the collection scope. |
| URLhausdark_web | ok10 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| VirusTotal Community IOC enrichmentresearch | ok4 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| VulnCheck KEVkev | ok500 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
| Vulnerability Lookupcve | ok30 records | Checked โ no match | The source completed, but none of its retained records matched this story. |
Additional verified pages 8 opened outside the registered collection
Vulnerability & exploitation4
Vendor & gov advisories4
CISA records exploitation in the wild, known ransomware use, a 1 July 2026 addition date and a 4 July remediation deadline.
CISA states that CVE-2026-45659 was added based on evidence of active exploitation.
Microsoft describes authenticated network-based remote code execution and confirms that May 2026 updates addressed the flaw.
NVD corroborates the SharePoint deserialisation weakness, CVSS 8.8 rating and CISA KEV status.