On August 11, 2026, CISA confirmed that ransomware groups are actively exploiting CVE-2026-45659 in Microsoft SharePoint on-premises. The statement arrives more than a month after the vulnerability was added to the KEV catalog, yet Microsoft has not updated its advisory to reflect the active exploitation status. The vendor's silence leaves organizations without a unified signal on the actual risk.
- CISA confirmed on August 11, 2026, that ransomware gangs are abusing CVE-2026-45659, an RCE flaw in SharePoint Server [SOURCE 1]
- CISA had already added the CVE to the KEV catalog on July 1, 2026, with a three-day mitigation deadline for federal agencies [SOURCE 1, SOURCE 6]
- Shadowserver detects over 8,500 SharePoint servers exposed online, of which over 200 remain unpatched against this specific vulnerability [SOURCE 1]
- Microsoft released patches in May 2026 for SharePoint Enterprise Server 2016, Server 2019, and Subscription Edition, but has not updated the advisory with the "exploited" tag [SOURCE 1]
The Mechanism: Deserialization of Untrusted Data with Minimal Privileges
CVE-2026-45659 stems from an untrusted data deserialization weakness in Microsoft SharePoint's data handling. According to the NVD record, the attack vector is network-based (AV:N), attack complexity is low (AC:L), and authentication requires only low privileges (PR:L). The flaw requires no user interaction (UI:N) and has a complete impact on confidentiality, integrity, and availability (C:H/I:H/A:H).
This combination means an attacker with low-level authenticated access can execute arbitrary code on the target server without complex technical prerequisites. The automatable nature of the exploitation, typical of deserialization vulnerabilities in enterprise applications, lowers the barrier for threat actors with proven ransomware tooling.
The Disclosure Gap: CISA Says "Ransomware," Microsoft Does Not Confirm
The critical issue is procedural, not technical. CISA publicly attributed CVE-2026-45659 to ransomware campaigns on August 11, 2026. Microsoft, which released security patches in May 2026 for the three affected on-premises versions, has not subsequently updated its advisory to signal active exploitation status.
This misalignment creates an operational problem for security teams that monitor vendor advisories as a primary source for prioritization. When the government agency classifies a flaw as a KEV with confirmed ransomware exploitation while the vendor maintains a low profile, organizations must correlate multiple sources for an accurate risk assessment. The dossier does not specify the reasons for this delay in coordinated disclosure.
The Numeric Indicator: Over 200 Exposed and Unpatched Servers
"Shadowserver currently tracks over 8,500 Microsoft SharePoint servers exposed online, with over 200 of them unpatched against the CVE-2026-45659 vulnerability"
Shadowserver data provides a concrete measure of residual risk. Of over 8,500 internet-exposed SharePoint servers, over 200 remain vulnerable to CVE-2026-45659 at the time of detection. These systems represent immediate targets for active ransomware operators, with an exposure window stretching from the May patch release to potential remediation.
The figure carries weight in a precise historical context. According to BleepingComputer citing CISA data, since November 2021 the agency has flagged 14 SharePoint vulnerabilities as actively exploited, and 8 of those — more than half — have been used in ransomware attacks. The pattern is established: SharePoint on-premises is a recurring vector for initial compromise of enterprise infrastructure.
What to Do Now
- Immediately apply the patches Microsoft released in May 2026 for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition [SOURCE 1]
- Integrate AMSI into SharePoint web applications and verify Microsoft Defender Antivirus configuration for detection and remediation, as recommended by CISA [SOURCE 1, SOURCE 3]
- Ensure threat intelligence processes do not rely exclusively on vendor advisories, given the documented delay in the exploitation tag for this specific vulnerability
- Check internet exposure of on-premises SharePoint servers and reduce attack surface where public access is not strictly necessary
The Takeaway: When the Vendor Advisory Is No Longer Enough
The CVE-2026-45659 case raises a structural question about enterprise vulnerability governance. Organizations have built patch management workflows around official vendor signals: CVSS severity, update availability, exploitation indicators. When the government signal and the commercial signal diverge on the same flaw, the workflow fails unless it is designed to integrate sources outside the traditional supply chain.
CISA imposed a three-day deadline on federal agencies between July 1 and July 4, 2026. Other organizations face no analogous mandates, but Microsoft's delay in publicly acknowledging the exploitation status has likely slowed the response of a significant portion of the installed base. The effect is a temporal distribution of risk: those with CISA visibility acted first; those waiting for the vendor signal acted last. The source does not specify how many servers were compromised in this intermediate window, but the structure of the misalignment itself is a relevant data point for anyone designing vulnerability management programs.
Sources
- https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-flaw-now-exploited-in-ransomware-attacks/
- https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040
- https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations
- https://www.cybersecuritydive.com/news/microsoft-sharepoint-attack-new-exploit/825797/
- https://thehackernews.com/2026/03/cisa-warns-of-zimbra-sharepoint-flaw.html
- https://nvd.nist.gov/vuln/detail/CVE-2026-45659
- https://www.cve.org/CVERecord?id=CVE-2026-32201
- https://nvd.nist.gov/vuln/detail/CVE-2026-50522
- https://nvd.nist.gov/vuln/detail/CVE-2026-32201
- https://nvd.nist.gov/vuln/detail/CVE-2026-56164
Information verified against cited sources and current as of publication.