Full research report

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

Original reporting โ†—
โ˜… Threat intelligence assessment high confidence

Executive assessment

CVE-2026-45659 is an important-severity SharePoint Server vulnerability in which unsafe deserialisation can give a low-privileged authenticated attacker remote code execution. Microsoft's affected-product data confirms three supported on-premises SharePoint lines and identifies the May 2026 fixed builds. CISA's later evidence supersedes Microsoft's unchanged exploitation flag for operational prioritisation: the flaw is in KEV and is explicitly marked as known in ransomware campaigns. The public records reviewed do not reveal which ransomware operation used it, against whom, or whether reusable exploit code is publicly available.

What happened

Microsoft published CVE-2026-45659 on 21 May 2026 for a SharePoint Server remote-code-execution vulnerability already addressed by May security updates. CISA added it to the Known Exploited Vulnerabilities catalogue on 1 July after finding evidence of active exploitation and subsequently marked it as known to be used in ransomware campaigns. The separately supplied CVE-2026-33825 concerns Microsoft Defender and is contextual reporting, not the SharePoint event investigated here.

Affected scope

Microsoft identifies SharePoint Enterprise Server 2016, SharePoint Server 2019 and SharePoint Server Subscription Edition as affected. The vulnerability is remotely reachable over a network but requires an authenticated account with at least Site Member permissions; exposed and unpatched on-premises servers are therefore the priority.

Technical assessment

CVE-2026-45659 is a CWE-502 deserialisation-of-untrusted-data weakness. A low-privileged authenticated attacker can cause a vulnerable SharePoint server to process unsafe data and execute code remotely, with potential loss of confidentiality, integrity and availability. CISA confirms exploitation and ransomware association, but the reviewed public evidence does not identify a ransomware family, actor, victim or public exploit implementation.

Recommended defensive actions

  1. Apply the relevant May 2026 or later SharePoint security update to every affected farm and confirm all servers meet or exceed the fixed build.
  2. Inventory internet-exposed SharePoint Server deployments and restrict external access wherever it is not operationally required.
  3. Audit Site Member and other authenticated SharePoint accounts, revoke unnecessary access and investigate anomalous or recently created accounts.
  4. Hunt for suspicious authenticated SharePoint requests, unexpected child processes, newly written executable or script content, and persistence introduced before patching.
  5. Verify successful update installation across every SharePoint server rather than relying solely on central deployment status.

Uncertainties and evidence gaps

  • CISA does not publicly identify the ransomware group, malware family, victims or incident count behind the ransomware designation.
  • Microsoft's record still states that exploitation is not confirmed, contradicting CISA's later assessment; CISA is stronger for current exploitation status because its KEV entry explicitly rests on exploitation evidence and records ransomware use.
  • No public proof-of-concept or independently verified exploit code for CVE-2026-45659 was found in the reviewed sources.
  • The supplied claim that more than 200 exposed servers remained unpatched could not be verified from a working Shadowserver source page.

Vulnerability flow

Defender-oriented path reconstructed only from sourced report findings. Unknown stages are omitted.

AccessNetwork access to a vulnerable SharePoint Server plus a valid authenticated account with at least Site Member permissions.
ComponentThe SharePoint Server boundary that deserialises attacker-influenced data.
MechanismUnsafe deserialisation permits authenticated, attacker-controlled data to trigger code execution.
ImpactRemote code execution with possible compromise of SharePoint data and server confidentiality, integrity and availability; CISA associates observed exploitation with ransomware campaigns.
DetectionReview authenticated SharePoint traffic and audit records for anomalous requests, then correlate them with unexpected worker-process child processes, file creation, security-control changes and encryption activity.
MitigationInstall the applicable May 2026 or later update: fixed builds include 16.0.5552.1002 for SharePoint Enterprise Server 2016, 16.0.10417.20128 for SharePoint Server 2019 and 16.0.19725.20280 for Subscription Edition.
Exploitation status

Confirmed active exploitation; CISA marks CVE-2026-45659 as known to be used in ransomware campaigns, but no public proof-of-concept was verified.

The investigation separated the current SharePoint ransomware story from contextual reporting about CVE-2026-33825. Microsoft and NVD established the affected products, authenticated attack prerequisite and deserialisation mechanism, while CISA supplied the stronger evidence that exploitation is occurring and is associated with ransomware. No verified public proof-of-concept, named actor, malware family or victim reporting was found, so attribution remains open.

  1. Did the supplied article provide independently reviewable evidence for the headline?
    Opened the supplied BleepingComputer URL.
    bleepingcomputer.com โ†—

    The site returned an automated security-verification page rather than accessible article content.

    why The article could not serve as a verified citation, so the assessment had to rely on accessible primary records.

  2. What weakness and exploitation status do government vulnerability records assign to CVE-2026-45659?
    Read the NVD vulnerability record.
    nvd.nist.gov โ†—

    NVD describes authenticated network code execution through deserialisation of untrusted data, assigns Microsoft's CVSS 3.1 score of 8.8 and identifies the CVE as present in CISA KEV.

    why This corroborated the technical mechanism and established that the event concerns a real SharePoint vulnerability rather than CVE-2026-33825.

  3. What does Microsoft say about prerequisites, disclosure and remediation timing?
    Read Microsoft's structured vulnerability advisory.
    api.msrc.microsoft.com โ†—

    Microsoft says an authenticated attacker with Site Member permissions can execute code over a network and that May 2026 updates addressed the vulnerability; its record still labels exploitation as unconfirmed.

    why This established the access requirement and patch timing while exposing a material status discrepancy with CISA.

  4. Does CISA explicitly confirm exploitation and ransomware use?
    Filtered and read CISA's KEV catalogue entry for the CVE.
    cisa.gov โ†—

    CISA lists CVE-2026-45659 as known exploited, marks ransomware use as known, and records addition on 1 July 2026 with remediation due by 4 July.

    why CISA provides the decisive evidence for both current exploitation and the ransomware association.

  5. Was the KEV addition itself based on active-exploitation evidence?
    Read CISA's 1 July alert.
    cisa.gov โ†—

    CISA states that it added CVE-2026-45659 based on evidence of active exploitation and urges prioritised remediation.

    why This independently confirms the basis of the KEV designation, although it does not disclose incidents or actors.

  6. Exactly which products and fixed builds are documented?
    Queried Microsoft's affected-product record.
    api.msrc.microsoft.com โ†—

    Microsoft lists SharePoint Enterprise Server 2016, SharePoint Server 2019 and Subscription Edition, with fixed builds 16.0.5552.1002, 16.0.10417.20128 and 16.0.19725.20280 respectively.

    why This resolved the affected scope and enabled specific, verifiable patch guidance.

  7. Could the reported exposure count be independently verified?
    Opened the apparent Shadowserver vulnerable-SharePoint reporting page.
    shadowserver.org โ†—

    The URL returned a 404 page and supplied no exposure data.

    why The claimed count of exposed and unpatched servers was excluded from confirmed findings and retained as an evidence gap.

MalwareUnspecified ransomware
TargetsOrganisations operating on-premises Microsoft SharePoint ServerInternet-exposed SharePoint Server deploymentsUS Federal Civilian Executive Branch agencies
Related CVEs CVE-2026-45659

Research coverage

All 68 registered source leaves were evaluated for this run: 61 completed, 0 were unavailable, 0 failed and 7 were disabled. For this story, 6 registered sources supplied useful evidence (4 primary, 1 corroborating, 1 contextual and 0 PoC/exploit references). 55 completed sources contained no matched information for this story.

Primary evidence Independent corroboration Operational context PoC reference Checked โ€” no match Unavailable Failed Disabled
Complete source-by-source audit 68 sources
SourceRun resultValueWhy it was useful โ€” or not
BleepingComputernews ok15 records Primary evidence1 matched items Published the source report used to frame and date the event.
CISA KEVkev ok1665 records Primary evidence4 matched items Confirmed that a related CVE is listed in CISA's Known Exploited Vulnerabilities catalogue. Supplied a vendor or government advisory opened and verified during focused research.
Microsoft MSRCvendor_advisory ok1590 records Primary evidence1 matched items Supplied a vendor or government advisory opened and verified during focused research.
NVDcve ok900 records Primary evidence1 matched items Supplied a vendor or government advisory opened and verified during focused research.
CISA Alertsnews ok empty0 records Corroborating1 matched items A page from this source was opened and verified during focused research.
FIRST EPSSepss ok Context2 matched items Added exploitation-probability context; EPSS does not itself prove exploitation.
AlienVault OTXdark_web ok10 records Checked โ€” no match The source completed, but none of its retained records matched this story.
CIRCL CVEcve ok30 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Cisco PSIRTvendor_advisory ok5323 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Cisco Talosnews ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI CVE most exploiteddeepdarkcti ok94 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI Discorddeepdarkcti ok7 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI exploitsdeepdarkcti ok24 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI forumsdeepdarkcti ok264 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI malware as a servicedeepdarkcti ok7 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI malware samplesdeepdarkcti ok3 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI marketsdeepdarkcti ok127 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI phishingdeepdarkcti ok19 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI ransomware gangsdeepdarkcti ok680 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI RATsdeepdarkcti ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI Telegram infostealerdeepdarkcti ok130 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI Telegram threat actorsdeepdarkcti ok1008 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI Twitter threat actorsdeepdarkcti ok39 records Checked โ€” no match The source completed, but none of its retained records matched this story.
DNSDumpster domain IOC enrichmentresearch ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Exploit-DBexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Fortinet PSIRTvendor_advisory disabled Disabled Disabled in the source registry; no check was attempted.
GitHub topic: cveresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GitHub topic: exploitresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GitHub topic: penetration-testingresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GitHub topic: pocresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GitHub topic: vulnerabilityresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GreyNoiseexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
KrebsOnSecuritynews ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
LinkedIn RSS proxy feeds (disabled)research disabled Disabled Disabled in the source registry; no check was attempted.
MalwareBazaardark_web ok10 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #cveresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #cybersecurityresearch ok12 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #exploitresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #infosecresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #malwareresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #ransomwareresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #threatintelresearch ok14 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #vulnerabilityresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Metasploit module metadataexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Microsoft Securitynews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
MISP Galaxyresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
MISP threat actor galaxyactor ok0 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Palo Alto Networks PSIRTvendor_advisory ok25 records Checked โ€” no match The source completed, but none of its retained records matched this story.
ProjectDiscovery nuclei templatesexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Rapid7news ok3 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Reddit r/AskNetsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/cybersecurity (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/malware (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/netsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/ReverseEngineering (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
SANS ISCnews ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Shadowserver public aggregate honeypot observationsexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Shodanresearch ok7 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Sigma Rulesresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Sophos IOCsresearch ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
The Hacker Newsnews ok15 records Checked โ€” no match The source completed, but none of its retained records matched this story.
ThreatFoxthreat_intelligence ok100 records Checked โ€” no match The source completed, but none of its retained records matched this story.
UK NCSCnews ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Unit42 IOCsresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
URLhausdark_web ok10 records Checked โ€” no match The source completed, but none of its retained records matched this story.
VirusTotal Community IOC enrichmentresearch ok4 records Checked โ€” no match The source completed, but none of its retained records matched this story.
VulnCheck KEVkev ok500 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Vulnerability Lookupcve ok30 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Additional verified pages 8 opened outside the registered collection
Vulnerability & exploitation4
CVE-2026-45659 CISA KEV Microsoft SharePoint Server ยท added 2026-07-01 ยท used in ransomware CISA catalog โ†—
CVE-2026-33825 CISA KEV Microsoft Defender ยท added 2026-04-22 ยท used in ransomware CISA catalog โ†—
CVE-2026-33825 EPSS 6.7% 93th percentile exploitation probability
CVE-2026-45659 EPSS 9.1% 95th percentile exploitation probability
Vendor & gov advisories4
CISA Known Exploited Vulnerabilities Catalog โ€” CVE-2026-45659 cisa.gov โ†—

CISA records exploitation in the wild, known ransomware use, a 1 July 2026 addition date and a 4 July remediation deadline.

CISA Adds One Known Exploited Vulnerability to Catalog cisa.gov โ†—

CISA states that CVE-2026-45659 was added based on evidence of active exploitation.

Microsoft Security Response Center โ€” CVE-2026-45659 api.msrc.microsoft.com โ†—

Microsoft describes authenticated network-based remote code execution and confirms that May 2026 updates addressed the flaw.

NVD โ€” CVE-2026-45659 nvd.nist.gov โ†—

NVD corroborates the SharePoint deserialisation weakness, CVSS 8.8 rating and CISA KEV status.