ctipilot.ch
← Back to the live brief
NOTABLECVE-2026-45659exploitedupdateNATOA1vulnerability

UPDATE — CISA now records the already-exploited SharePoint deserialization flaw CVE-2026-45659 as used in ransomware campaigns, changing what an unpatched farm risks

discovered 2026-08-13 05:02 UTCrun 2026-08-13T0412Z-intel2 sourcesmulti-source

UPDATE · originally covered CVE-2026-45659 — Microsoft SharePoint Server: authenticated deserialization RCE, now KEV-listed (2026-07-02)

the original entry recorded CISA's 1 July catalogue addition for CVE-2026-45659 as the first public confirmation that this SharePoint deserialization path was being exploited, against a Microsoft advisory that still rated it "Exploitation Less Likely". The catalogue entry has since gained a second flag.

Queried directly this run, the Known Exploited Vulnerabilities catalog at version 2026.08.11 records CVE-2026-45659 with its ransomware-campaign-use field set to "Known" (CISA KEV catalog, 2026-08-11). That the value changed on 11 August, rather than having been present since the July addition, is reported separately: CISA "confirmed that a high-severity Microsoft SharePoint remote code execution vulnerability (CVE-2026-45659), flagged as actively exploited since early July, is now also being exploited by ransomware gangs" (BleepingComputer, 2026-08-12). The same reporting notes that of the fourteen SharePoint vulnerabilities the agency has flagged as actively exploited since November 2021, eight have also been exploited in ransomware attacks.

The flaw itself is unchanged from the original coverage: deserialization of untrusted data reachable by an attacker holding at least Site Member permissions, CVSS 8.8, patched by Microsoft on 2026-05-21. No source names the operation responsible, its victims, or how the required authenticated access is obtained in these campaigns, and none is asserted here.

On Tuesday, CISA also confirmed that a high-severity Microsoft SharePoint remote code execution vulnerability (CVE-2026-45659), flagged as actively exploited since early July, is now also being exploited by ransomware gangs.

BleepingComputer 2026-08-12

Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.

CISA Known Exploited Vulnerabilities catalog 2026-08-11

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.2

Initial Access TA0001
T1190Exploit Public-Facing Application

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.