Ransomware Campaigns Exploit SharePoint RCE Flaw CVE-2026-45659, CISA Warns

CISA confirms ransomware groups are actively exploiting CVE-2026-45659, a SharePoint deserialization/RCE flaw that allows low-privilege attackers to execute arbitrary code on unpatched servers, with activity dating back to early July. Federal agencies were ordered to patch within three days and to monitor for signs of exploitation, applying the latest fixes and enabling AMSI integration and Defender detections. Shadowserver tracks thousands of internet-exposed SharePoint servers, including hundreds unpatched; CISA notes 14 exposed SharePoint vulns have been exploited since 2021, eight in ransomware campaigns. A second high-severity flaw, CVE-2026-33825 (BlueHammer), was also linked to attacks last month, though Microsoft has not confirmed wild exploitation.
- CISA: Microsoft SharePoint flaw now exploited in ransomware attacks BleepingComputer
- Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks thehackernews.com
- FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure The Record from Recorded Future News
- WARNING: SonicWall SMA1000 Zero-Days Exploited To Breach Enterprise Networks LinkedIn
- NSA Joins FBI and Others in Releasing Guidance to Defend Against Gunra Ransomware National Security Agency (NSA) (.gov)
Reading Insights
0
19
3 min
vs 4 min read
85%
693 → 102 words
Want the full story? Read the original article
Read on BleepingComputer