// Microsoft 365CRITICAL
CISA confirmed that ransomware gangs are actively exploiting CVE-2026-45659, a high-severity Microsoft SharePoint remote code execution vulnerability. The flaw, tracked since early July, stems from unsafe deserialization and allows low-privilege attackers to execute arbitrary code on unpatched servers with low complexity. CISA added it to the Known Exploited Vulnerabilities Catalog on July 1, 2026, and now reports widespread ransomware abuse.
// Get alerts for Microsoft 365