CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog after confirming active exploitation of a high-severity remote code execution flaw in on-premises Microsoft SharePoint Server. The vulnerability stems from deserialization of untrusted data (CWE-502) and carries a CVSS 8.8 score. It affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition below patched versions, and can be exploited over the network by an authenticated attacker with low privileges such as Site Member, without user interaction.
Microsoft issued fixes in its May 2026 security updates, later clarifying that the CVE had been inadvertently omitted from the initial update list. CISA set a July 4, 2026 remediation deadline for federal civilian agencies under Binding Operational Directive 22-01, while public reporting said the exact vulnerable SharePoint component, gadget chain, payload delivery method, and any connection to ransomware activity had not yet been disclosed. Security guidance accompanying the KEV listing urged organizations to patch immediately and review exposed SharePoint environments for signs of compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Microsoft Incident Response reported that Storm-2603 has exploited on-premises SharePoint since mid-2025 to deploy Warlock ransomware. The activity reportedly involved post-compromise tooling including Cloudflare tunneling, Zoho Assist, Visual Studio Code SSH, and the vulnerable driver NSecKrnl.sys.
Following CISA's KEV addition, federal civilian agencies were given a remediation deadline of July 4, 2026 for CVE-2026-45659. Organizations were urged to patch immediately and investigate for signs of compromise.
CISA warned that CVE-2026-33825 is being actively exploited in ransomware attacks. The warning identified the Microsoft Defender privilege-escalation flaw as an in-the-wild threat.
Kubota USA said unauthorized access to certain network systems occurred between March 16, 2026 and April 20, 2026. The company later determined that HR-managed files were accessed, including files containing personal information of employees and their dependents.
Microsoft included fixes for CVE-2026-45659 in its May 2026 security updates for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. Microsoft later clarified that the CVE had been inadvertently omitted from the initial update list.
On July 1, 2026, CISA added CVE-2026-45659 to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The flaw is a high-severity remote code execution issue in on-premises Microsoft SharePoint Server caused by deserialization of untrusted data.
Kubota said it mailed notification letters to affected individuals on June 30, 2026. The company also offered free identity monitoring services through Kroll.
Microsoft released a fix for CVE-2026-33825 on April 14, 2026. According to Microsoft, the flaw affects Microsoft Defender and allows an authenticated attacker to achieve privilege escalation on affected systems.
CVE-2026-33825, also called BlueHammer, was publicly disclosed on April 2, 2026 before a patch was available. The disclosure was tied to a researcher using the aliases Chaotic Eclipse and Nightmare Eclipse.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
codeby.net
Open sourcecyberveille.ch
Open sourcecyberveille.ch
Open sourcecyberveille.ch
Open sourcethreataft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.