CISA: SharePoint RCE Flaw Now Used in Ransomware
🔒 CISA has confirmed that ransomware groups are actively exploiting a high-severity Microsoft SharePoint remote code execution flaw, tracked as CVE-2026-45659. The vulnerability arises from deserialization of untrusted data and allows low-privilege attackers to execute arbitrary code on unpatched SharePoint servers. Agencies were ordered to patch quickly and monitor for exploitation, while Shadowserver reports thousands of exposed SharePoint instances, some still unpatched.
