Ransomware Campaigns Exploit SharePoint RCE Flaw CVE-2026-45659, CISA Warns

1 min read
Source: BleepingComputer
Ransomware Campaigns Exploit SharePoint RCE Flaw CVE-2026-45659, CISA Warns
Photo: BleepingComputer
TL;DR Summary

CISA confirms ransomware groups are actively exploiting CVE-2026-45659, a SharePoint deserialization/RCE flaw that allows low-privilege attackers to execute arbitrary code on unpatched servers, with activity dating back to early July. Federal agencies were ordered to patch within three days and to monitor for signs of exploitation, applying the latest fixes and enabling AMSI integration and Defender detections. Shadowserver tracks thousands of internet-exposed SharePoint servers, including hundreds unpatched; CISA notes 14 exposed SharePoint vulns have been exploited since 2021, eight in ransomware campaigns. A second high-severity flaw, CVE-2026-33825 (BlueHammer), was also linked to attacks last month, though Microsoft has not confirmed wild exploitation.

Share this article

Reading Insights

Total Reads

0

Unique Readers

19

Time Saved

3 min

vs 4 min read

Condensed

85%

693102 words

Want the full story? Read the original article

Read on BleepingComputer