V-Help
← All news
Security

Cybercriminals Exploit Microsoft SharePoint Vulnerability in Ransomware Attacks

Cybercriminals Exploit Microsoft SharePoint Vulnerability in Ransomware Attacks

Photo: BleepingComputer

Quick answer

Cybercriminals are leveraging the critical CVE-2026-45659 vulnerability in Microsoft SharePoint to conduct ransomware attacks.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that cybercriminal groups are actively exploiting a critical vulnerability in Microsoft SharePoint to distribute ransomware. The vulnerability, identified as CVE-2026-45659, allows attackers to remotely execute arbitrary code on servers with low access privileges.

The issue stems from insecure data deserialization, making attacks relatively easy to execute. Although Microsoft released patches for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition in May, many organizations have yet to update their systems. CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog and mandated federal agencies to remediate it within three days.

According to the Shadowserver group, over 8,500 SharePoint servers remain exposed on the internet, with more than 200 still unprotected against CVE-2026-45659. Experts recommend that administrators not only apply updates but also enhance system monitoring for suspicious activity. Special attention should be given to integrating Windows Antimalware Scan Interface (AMSI) and using Microsoft Defender Antivirus to detect exploitation attempts.

It is worth noting that this is not the first instance of SharePoint vulnerabilities being targeted in ransomware attacks. Since November 2021, CISA has recorded 14 actively exploited vulnerabilities in this product, eight of which were used to distribute ransomware. In June, the agency also reported the exploitation of another critical vulnerability in Microsoft Defender related to privilege escalation.

Common questions

What is the CVE-2026-45659 vulnerability in Microsoft SharePoint?
CVE-2026-45659 is a critical remote code execution vulnerability related to insecure data deserialization. It allows attackers with low privileges to execute arbitrary code on vulnerable SharePoint servers without complex attack conditions.
Which versions of SharePoint are affected?
The vulnerability impacts SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. Microsoft released patches for these versions in May 2024.
How can organizations protect against this vulnerability?
Organizations should install the latest security updates from Microsoft, enable Windows Antimalware Scan Interface (AMSI) integration for SharePoint web applications, and use Microsoft Defender Antivirus to detect and block exploitation attempts.
Share:

Dzen feed: /feed/dzen.xml · RSS: /feed.xml

Why trust this

Prepared by the V-Help editorial team from the primary source with a published date.

Published by: V-Help.ru news desk

Source: BleepingComputer