AI Stories on SHORT INFO are generated & curated with AI
unverified 12 Aug, 21:09

CISA confirms SharePoint deserialization flaw CVE-2026-45659 now exploited in ransomware attacks

CISA confirms a Microsoft SharePoint flaw patched in May is now used in ransomware attacks. CVE-2026-45659 lets low-privilege attackers run code on unpatched on-prem SharePoint Server 2016, 2019 and Subscription Edition via unsafe deserialization. Over 200 systems reportedly rema

CISA has confirmed that a Microsoft SharePoint vulnerability, CVE-2026-45659, is now being actively used in ransomware attacks. The flaw is an unsafe deserialization bug affecting on-premises SharePoint Server 2016, SharePoint Server 2019 and SharePoint Server Subscription Edition, allowing attackers with only low privileges to execute arbitrary code on affected servers. Microsoft patched the vulnerability in May. CISA added it to its Known Exploited Vulnerabilities catalog in July after confirming active exploitation, and by August that exploitation had escalated into full ransomware attacks. More than 200 SharePoint systems reportedly remain unpatched and exposed. One researcher has pointed to the China-linked group Storm-2603 as a likely operator, describing it as the only known actor with a repeatable ransomware playbook built specifically around this class of on-prem SharePoint deserialization flaws. CISA is urging organizations to install the latest security updates, verify patches were applied correctly, and monitor SharePoint servers for signs of compromise. The three-month gap between the May patch and the August ransomware wave shows how much internet-facing, on-premises infrastructure still lags behind vendor fixes, giving intrusion crews a long runway once a flaw becomes public knowledge. Sources: CISA, BleepingComputer, Cybersecurity Dive.

#cyber
Published on
RedditBlueskyXFacebookThreads