Microsoft SharePoint Bug Exposed in Ransomware Attacks
A high-severity bug in Microsoft SharePoint has been exploited since early July and used in ransomware attacks, according to an update to the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities (KEV) catalog.
The CVE-2026-45659 vulnerability was patched by Microsoft in late May but was added to the KEV on July 1. The agency did not provide further information about the ransomware attack, but a spokesperson for Microsoft recommended that customers apply the May security update to remain protected.
Denis Calderone, chief technology officer at Suzu Labs, said this case has the China-linked group Storm-2603 'written all over it.' He stated that CISA didn't name a threat actor, but Storm-2603 is the only known group that has built a repeatable ransomware operation specifically around on-prem SharePoint deserialization flaws.
Roman Sannikov, global research coordinator at iCounter, said CVE-2026-45659 is a low complexity, minimal privileges required deserialization flaw on an on-premises SharePoint Server. He stated that initial access brokers look for something reliable enough to weaponize at scale and sell, rather than something one group has to painstakingly develop and keep to itself.