Microsoft SharePoint vulnerability moves into ransomware territory
12 Aug 2026 · Active Exploitation · CISO Careers
CISA KEV Ransomware · on-premises SharePoint Server · update available
The critical SharePoint flaw tracked as CVE-2026-45659 is now being used in ransomware attacks.
What CISA confirmed
CISA has confirmed that threat actors are exploiting a critical vulnerability in Microsoft SharePoint in ransomware attacks. The vulnerability, CVE-2026-45659, affects on-premises SharePoint Server and can allow attackers to execute arbitrary code remotely. This is the sort of sentence that makes the person responsible for SharePoint suddenly very popular.
The update
Microsoft has released security updates addressing the vulnerability.
"We have a patch" sounds reassuring right up until someone asks how many SharePoint servers there are.
"Four."
"Good."
"…that we know about."
What to do now
Organizations running affected versions should prioritize patching, verify that systems are no longer exposed, and monitor for signs of compromise. The last part is easy to underestimate. If exploitation started before the patch, you are no longer doing ordinary vulnerability management. You are trying to establish whether the thing you just fixed was already used against you. Different meeting. Different people. Usually worse coffee.
The long tail of enterprise platforms
The incident is a reminder of the risk carried by vulnerabilities in widely deployed enterprise software. It follows the same shape as this week's LoadMaster entry: an edge-facing product, a compressed remediation window, and exploitation that did not wait for the patch cycle. The gap between disclosure and exploitation keeps getting shorter. SharePoint has a remarkable ability to outlive the people who deployed it. I have seen "temporary" instances survive reorganizations, migrations and the departure of the only person who knew why they existed. At some point the server stops being an application and becomes an archaeological site.
Sources · CISA, Known Exploited Vulnerabilities Catalog ↗ · Microsoft MSRC, Security update for CVE-2026-45659 ↗ · BleepingComputer, CISA: Microsoft SharePoint flaw now exploited in ransomware attacks ↗
← All dispatches