AI Stories on SHORT INFO are generated & curated with AI
unverified 06 Jul, 06:10

Microsoft SharePoint Server RCE CVE-2026-45659 actively exploited, added to CISA KEV with July 4 patch deadline, chained into ransomware

If your organization runs an internet-facing Microsoft $MSFT SharePoint Server, a remote code execution flaw (CVE-2026-45659) is now under active attack. CISA added it to its Known Exploited list with a July 4 federal patch deadline, and intruders are chaining it into ransomware.

Organizations that run Microsoft ($MSFT) SharePoint Server on internet-facing systems have a pressing patch to apply. A remote code execution vulnerability tracked as CVE-2026-45659, rated 8.8 on the severity scale, is now being exploited in live attacks. CISA has added it to its Known Exploited Vulnerabilities catalog and set a July 4 deadline for federal civilian agencies to fix it. The detail that makes this dangerous is the low bar to abuse it. An authenticated user with only Site Member level permissions, one of the most basic roles in SharePoint, can trigger the flaw and execute code on the server. That turns any compromised low-privilege account into a foothold. Incident responders report attackers chaining the bug into full ransomware operations, moving laterally and escalating to domain administrator. Reported victims span government, healthcare, finance, education and critical infrastructure, with unpatched internet-exposed servers the common thread. Microsoft issued fixes in May for the Subscription Edition, 2019 and 2016 releases. Source: CISA and The Hacker News.

Published on
XFacebookThreadsBluesky