CISA updated its Known Exploited Vulnerabilities catalog to mark CVE-2026-45659 in Microsoft SharePoint Server as linked to known ransomware campaign use, escalating concern around a flaw already tracked as actively exploited. The vulnerability is a deserialization of untrusted data issue that can let an authorized or low-privileged attacker execute arbitrary code over the network on unpatched SharePoint servers, and CISA continues to direct organizations to apply Microsoft mitigations under BOD 26-04.
The agency had previously added the bug to the KEV catalog and required Federal Civilian Executive Branch agencies to remediate it within three days, while also urging defenders to verify patch deployment, monitor SharePoint servers for signs of exploitation, shorten patching cycles, and enable AMSI integration and Microsoft Defender Antivirus detections. Reporting cited internet scans showing more than 8,500 exposed SharePoint servers, including more than 200 still unpatched against CVE-2026-45659, underscoring the ongoing exposure as ransomware operators adopt the exploit.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CISA updated the KEV catalog entry for CVE-2026-45659 to change known ransomware campaign use from "Unknown" to "Known," indicating the SharePoint flaw is associated with ransomware attacks.
CISA added CVE-2026-45659, a Microsoft SharePoint remote code execution vulnerability, to its Known Exploited Vulnerabilities catalog and required Federal Civilian Executive Branch agencies to remediate it within three days.
Microsoft released security updates in May for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition to address CVE-2026-45659.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
waterisac.org
Open sourcescworld.com
Open sourceheise.de
Open sourcecert.ug
Open sourcebleepingcomputer.com
Open sourcegithub.com
Open sourcecisa.gov
Open sourcecert.az
Open sourcegov.br
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.