Microsoft SharePoint Server vulnerability CVE-2026-45659 has been exploited in ransomware attacks, according to an update to the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog reported by SC World. The high-severity flaw carries a CVSS score of 8.8 and has been actively exploited since at least July.
The vulnerability is a deserialization flaw affecting on-premises SharePoint Server that requires minimal privileges and is relatively easy to exploit. Microsoft patched the vulnerability in May and said customers that applied the security update or have automatic updates enabled are protected. CISA has not identified the ransomware operation responsible for the attacks.
Security researchers told SC World the activity resembles previous operations by China-linked Storm-2603, which has targeted on-premises SharePoint and previously deployed Warlock ransomware. However, the latest ransomware activity has not been formally attributed to the group. The progression from an available patch in May to confirmed exploitation in July and ransomware activity in August underscores how quickly known vulnerabilities can become serious threats when systems remain unpatched.
For MSPs, the attacks are another reason to prioritize patch visibility across clients running on-premises infrastructure. MSPs should identify exposed SharePoint Server vulnerability risks, verify that Microsoft’s May security update has been applied and treat any still-unpatched systems as a priority, particularly now that ransomware exploitation has been confirmed.
Source: SC World












