CISA confirmed that ransomware gangs are abusing the actively exploited Microsoft SharePoint remote code execution flaw CVE-2026-45659, which allows attackers with low privileges to run arbitrary code on unpatched servers. The agency urged rapid patching and monitoring as more than 200 internet-exposed SharePoint servers remain unpatched, while also noting similar exploitation trends involving Microsoft Defender flaw CVE-2026-33825. #CVE-2026-45659 #MicrosoftSharePoint #CISA #CVE-2026-33825 #MicrosoftDefender
Keypoints
- CISA confirmed ransomware gangs are abusing CVE-2026-45659.
- The SharePoint flaw enables remote code execution on unpatched servers.
- CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog.
- Security teams were urged to patch, verify installation, and monitor for exploitation.
- Over 200 internet-exposed SharePoint servers remain unpatched, and Microsoft Defender CVE-2026-33825 was also linked to attacks.