CISA Reports Microsoft SharePoint Flaw Exploited by Ransomware

TL;DR. CISA has confirmed that a critical Microsoft SharePoint vulnerability, actively exploited by ransomware groups, allows low-privilege attackers to execute arbitrary code, despite Microsoft having released patches for the flaw. - The high-severity flaw, CVE-2026-45659, enables arbitrary code execution by low-privilege attackers. - Thousands of Microsoft SharePoint servers remain exposed and unpatched, leaving them vulnerable to attacks. - This vulnerability is the 14th actively exploited SharePoint flaw identified since November 2021.

Sources

Back to QLANKR News