bleeping-computer · Crawled Aug 11, 2026

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

Read original article ↗

AI Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are actively exploiting a high-severity remote code execution vulnerability, CVE-2026-45659, in Microsoft SharePoint. The flaw stems from deserialization of untrusted data, allowing low-privileged attackers to execute arbitrary code on unpatched servers with low attack complexity. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on July 1, mandating federal agencies to patch within three days, and warned that over 200 internet-exposed SharePoint servers remain unpatched despite available updates.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.