Ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, tracked as CVE-2026-45659.

The flaw, stemming from a deserialization of untrusted data weakness, allows attackers with low privileges to execute arbitrary code on unpatched SharePoint servers.

8.8 CVSS

Severity score for CVE-2026-45659, categorized as 'high' risk.

Microsoft released security updates for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition in May. For CVE-2026-45659, Microsoft stated that 'an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.' S2 notes that Microsoft estimated exploitation as 'less likely' with a CVSS Temporal Score of 7.7 at the time.

CISA adds to KEV catalog

The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-45659 to its Known Exploited Vulnerabilities (KEV) Catalog on July 1 and ordered Federal Civilian Executive Branch (FCEB) agencies to secure their servers within three days. CISA warned that this type of vulnerability 'poses significant risks to the federal enterprise.'

Exposed servers and unpatched instances

Shadowserver tracks over 8,500 Microsoft SharePoint servers exposed online, with over 200 unpatched against CVE-2026-45659. According to S2, approximately half of these unpatched servers are in the US and about a quarter in Europe. Shadowserver also reported approximately a dozen unpatched servers in Germany, low single digits in Austria and Switzerland, and noted that in early June there were about 1,100 unpatched instances online.

Broader context and related vulnerabilities

Since November 2021, CISA has flagged 14 actively exploited Microsoft SharePoint vulnerabilities, eight of which were exploited in ransomware attacks.

In June, CISA confirmed that ransomware gangs exploit a high-severity Microsoft Defender privilege escalation vulnerability dubbed BlueHammer (CVE-2026-33825). That flaw was leaked by a security researcher known as 'Nightmare Eclipse' in early April along with proof-of-concept exploit code.

New PoC exploit for another SharePoint flaw

A proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, tracked as CVE-2026-55040, was published by cybersecurity company Rapid7. The flaw is an authentication bypass in the JWT token validation pipeline and can be exploited by attackers without privileges to perform operations as a SharePoint site user or administrator.

Microsoft patched CVE-2026-55040 in July 2026 Patch Tuesday updates and stated that 'the authentication feature could be bypassed as this vulnerability allows impersonation.' Exploiting it could allow an attacker to disclose files and modify data, but not impact system availability.

Rapid7 security researcher Stephen Fewer published a detailed technical write-up and the PoC on Tuesday. Threat intelligence company Defused reported that the exploit code has already been weaponized in attacks targeting its honeypots, warning that 'Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots.'

CISA warned network defenders on July 15 to secure their SharePoint servers against potential CVE-2026-55040 attacks.