CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
CISA confirmed that ransomware gangs are abusing the actively exploited Microsoft SharePoint remote code execution flaw CVE-2026-45659, which allows attackers with low privileges to run arbitrary code on unpatched servers. The agency urged rapid patching and monitoring as more than 200 internet-exposed SharePoint servers remain unpatched, while also noting similar exploitation trends involving Microsoft Defender flaw CVE-2026-33825. #CVE-2026-45659 #MicrosoftSharePoint #CISA #CVE-2026-33825 #MicrosoftDefender

Keypoints

  • CISA confirmed ransomware gangs are abusing CVE-2026-45659.
  • The SharePoint flaw enables remote code execution on unpatched servers.
  • CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog.
  • Security teams were urged to patch, verify installation, and monitor for exploitation.
  • Over 200 internet-exposed SharePoint servers remain unpatched, and Microsoft Defender CVE-2026-33825 was also linked to attacks.

Read More: https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-flaw-now-exploited-in-ransomware-attacks/