
The US Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities catalog to confirm that ransomware groups are actively abusing CVE-2026-45659, a high-severity deserialization flaw in Microsoft SharePoint. The vulnerability affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. It allows an attacker with only low-level privileges to execute arbitrary code on an unpatched server without needing prior knowledge of the system — making it straightforward to weaponize at scale.
CISA first added CVE-2026-45659 to its KEV list on July 1, ordering US federal civilian agencies to patch within three days. Tuesday’s update is significant because it explicitly links the flaw to ransomware activity, raising the threat level for any organization still running an unpatched server. According to Shadowserver, which continuously monitors internet-facing systems, over 8,500 SharePoint servers remain exposed online — more than 200 of them still unpatched against this specific vulnerability. Microsoft released fixes in May and has not yet independently confirmed active exploitation in its own advisory, but CISA’s updated KEV entry carries its own weight: the agency requires affirmative evidence of exploitation before making that designation. This is the 14th actively exploited SharePoint vulnerability CISA has flagged since November 2021, and the eighth linked specifically to ransomware attacks.
How to check if you’re affected
Affected products are SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. Check your installed version against Microsoft’s May 2026 patch release and confirm the CVE-2026-45659 update is applied. CISA also recommends enabling Windows Antimalware Scan Interface (AMSI) integration for SharePoint web applications and running Microsoft Defender Antivirus scans to detect any signs of prior compromise. If you’re unsure whether your server has been patched, Shadowserver’s public dashboard lists unpatched internet-exposed servers by country and organization.
