
CISA confirmed at present that ransomware gangs have begun abusing a high-severity Microsoft SharePoint distant code execution vulnerability, which has been flagged as actively exploited since early July.
Tracked as CVE-2026-45659, this safety flaw stems from a deserialization of untrusted knowledge weak point and permits attackers with low privileges to execute arbitrary code on unpatched SharePoint servers.
It can be exploited in low-complexity assaults as a result of (as Microsoft defined in Might when it launched safety updates for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Version) “an attacker doesn’t require important prior information of the system and might obtain repeatable success with the payload in opposition to the weak part.”
The U.S. Cybersecurity and Infrastructure Safety Company (CISA) added the vulnerability to its Identified Exploited Vulnerabilities Catalog (KEV) on July 1, ordering Federal Civilian Government Department (FCEB) businesses to safe their servers inside three days.
“The sort of vulnerability is a frequent assault vector for malicious cyber actors and poses important dangers to the federal enterprise,” the U.S. cybersecurity company warned on the time.
In a subsequent advisory, the cybersecurity company additionally urged safety groups to watch affected servers for indicators of exploitation, apply Microsoft’s newest patches, confirm profitable set up, and shorten patching cycles.
It additionally really useful enabling Home windows Antimalware Scan Interface (AMSI integration for SharePoint net functions and utilizing Microsoft Defender Antivirus (MDAV) detections to detect and remediate compromise.
Web safety watchdog group Shadowserver at the moment tracks over 8,500 Microsoft SharePoint servers uncovered on-line, with over 200 of them unpatched in opposition to the CVE-2026-45659 vulnerability.

Whereas Microsoft has but to replace the CVE-2026-45659 advisory to tag it as exploited, CISA has now additionally flagged it as abused by ransomware gangs in a Tuesday replace to the KEV Catalog.
Since November 2021, the cybersecurity company has flagged 14 actively exploited Microsoft SharePoint vulnerabilities, with eight of them additionally exploited in ransomware assaults.
In June, CISA also confirmed that ransomware gangs now exploit a high-severity Microsoft Defender privilege escalation vulnerability (dubbed BlueHammer), which was additionally targeted as a zero-day to entry the Safety Account Supervisor (SAM) database, which comprises password hashes for native accounts.
The safety flaw (tracked CVE-2026-33825) was leaked by a safety researcher referred to as “Nightmare Eclipse” in early April, along with proof-of-concept exploit code.
Nonetheless, as with CVE-2026-45659, Microsoft has but to substantiate that the CVE-2026-33825 safety flaw is being exploited within the wild.
Safety groups log 54% of profitable assaults and alert on simply 14%. The remainder transfer by means of your setting unseen.
The Picus whitepaper exhibits how breach and assault simulation exams your SIEM and EDR guidelines so threats cease slipping by detection.

