CVE Tools
Back to feed
Exploited in the wild SharePoint Server ransomware Defender Antivirus Microsoft rce

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

BleepingComputer·By Sergiu Gatlan··2 min read
CVE Tools coverage

CISA has confirmed that ransomware campaigns are actively leveraging a high-severity remote code execution vulnerability in Microsoft SharePoint, identified as CVE-2026-45659. This flaw, which stems from improper handling of untrusted data, enables low-privilege attackers to execute arbitrary code on SharePoint Server 2016, 2019, and Subscription Edition instances with minimal effort. Although the vulnerability was added to the Known Exploited Vulnerabilities catalog in early July, recent updates indicate its specific use in ransomware operations.

Administrators are urged to verify that Microsoft’s latest security patches are installed and to monitor for signs of compromise using Microsoft Defender Antivirus detections.