
Ransomware Campaigns Exploit SharePoint RCE Flaw CVE-2026-45659, CISA Warns
CISA confirms ransomware groups are actively exploiting CVE-2026-45659, a SharePoint deserialization/RCE flaw that allows low-privilege attackers to execute arbitrary code on unpatched servers, with activity dating back to early July. Federal agencies were ordered to patch within three days and to monitor for signs of exploitation, applying the latest fixes and enabling AMSI integration and Defender detections. Shadowserver tracks thousands of internet-exposed SharePoint servers, including hundreds unpatched; CISA notes 14 exposed SharePoint vulns have been exploited since 2021, eight in ransomware campaigns. A second high-severity flaw, CVE-2026-33825 (BlueHammer), was also linked to attacks last month, though Microsoft has not confirmed wild exploitation.