CISA Reports Microsoft SharePoint Flaw Exploited by Ransomware
TL;DR. CISA has confirmed that a critical Microsoft SharePoint vulnerability, actively exploited by ransomware groups, allows low-privilege attackers to execute arbitrary code, despite Microsoft having released patches for the flaw. - The high-severity flaw, CVE-2026-45659, enables arbitrary code execution by low-privilege attackers. - Thousands of Microsoft SharePoint servers remain exposed and unpatched, leaving them vulnerable to attacks. - This vulnerability is the 14th actively exploited SharePoint flaw identified since November 2021.
- CISA confirmed the exploitation of a high-severity Microsoft SharePoint flaw (CVE-2026-45659) by ransomware gangs.
- The vulnerability allows remote code execution with low privileges and minimal attacker knowledge.
- Over 8,500 SharePoint servers are internet-exposed, with 200+ still unpatched against this specific flaw.
- CISA had previously ordered federal agencies to patch within three days and urged general security teams to monitor for exploitation.
Sources
- CISA: Microsoft SharePoint flaw now exploited in ransomware attacks — bleepingcomputer.com