Summary
- CISA now marks CVE-2026-45659 as known to be used in ransomware campaigns after adding the SharePoint flaw to its exploited-vulnerability catalogue in July.
- The vulnerability allows an authenticated attacker with low privileges to execute code on affected on-premises SharePoint Server installations.
- The development turns an existing patching problem into a documented ransomware exposure rather than a new SharePoint vulnerability.
An already exploited Microsoft SharePoint Server vulnerability has moved into ransomware operations, adding a new consequence to a flaw that organisations have had patches for since May.
Microsoft tracks CVE-2026-45659 as a deserialisation vulnerability affecting supported on-premises SharePoint Server products. A low-privileged authenticated attacker can exploit the weakness over a network to execute code on a vulnerable server. The US Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalogue on 1 July after exploitation was observed.
CISA has now changed the entry to mark the vulnerability as known to be used in ransomware campaigns. The agency has not publicly identified the ransomware operation involved, the organisations affected, or whether the flaw served as initial access in every incident associated with that classification. The update establishes ransomware use without resolving those wider questions.
Cyber Insider has previously covered the wider exploitation pressure around SharePoint, including the theft of server secrets and persistence risks, as well as a Swiss government incident involving compromised SharePoint accounts. The ransomware designation is a material development to that existing exposure rather than evidence of a newly discovered flaw.
CVE-2026-45659 carries a CVSS score of 8.8 and affects on-premises SharePoint Server rather than Microsoft 365’s hosted SharePoint service. Microsoft describes the weakness as deserialisation of untrusted data and released fixes for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. Exploitation requires an authorised account, but only relatively limited privileges are needed.
That requirement does not make the flaw irrelevant to ransomware operators. Enterprise intrusions frequently involve stolen accounts, compromised sessions, or access obtained through a separate vulnerability before attackers look for additional ways to execute code and expand control. SharePoint servers can also occupy trusted positions inside corporate environments, hold sensitive documents, and integrate with identity and application infrastructure.
The ransomware update therefore changes the evidence available for prioritisation. In July, organisations already had an actively exploited SharePoint vulnerability to manage. They now have confirmation that the same flaw has appeared in ransomware activity. For systems that remain exposed or were patched late, the question is no longer limited to whether an attacker could exploit the weakness, but whether previous exploitation may have established access before remediation.
That is particularly relevant because patching an exploited server and investigating an exploited server are different tasks. Updating software removes the vulnerable condition addressed by the patch, but it does not automatically remove accounts, web shells, stolen secrets, or other persistence created before the update. CISA’s earlier SharePoint guidance has focused on both remediation and examination for indicators of compromise across affected environments.
On-premises SharePoint has accumulated a series of actively exploited vulnerabilities over several years, with a number of previous entries in CISA’s catalogue also associated with ransomware. The pattern reflects both the value of the platform and the long tail of enterprise deployments that organisations continue to operate themselves rather than consume as a managed cloud service.
CISA’s latest classification does not establish a new emergency for every SharePoint customer, but it narrows the remaining uncertainty around attacker intent. CVE-2026-45659 is not only technically exploitable and observed in the wild; it has now entered the ransomware economy.



