CISA confirmed that ransomware gangs are actively exploiting CVE-2026-45659, a high-severity remote code execution vulnerability in Microsoft SharePoint, since early July 2026. The flaw stems from unsafe deserialization and allows low-privilege attackers to execute arbitrary code on unpatched SharePoint Enterprise Server 2016, 2019, and Subscription Edition instances with low-complexity attacks. Organizations should prioritize patching as ransomware operators have incorporated the exploit into active campaigns.
// Get alerts for Microsoft Azure