CISA has confirmed that ransomware gangs are now actively exploiting CVE-2026-45659, a high-severity Microsoft SharePoint remote code execution flaw first flagged as exploited in early July. For UK enterprises still running on-premises or hybrid SharePoint, this is the patch to prioritise above everything else this week.
View the data behind this chart
| Exposed online | Unpatched vs CVE-2026-4565… | |
|---|---|---|
| SharePoint servers | servers8500 | servers200 |
What CISA confirmed today
On 11 August, CISA updated its Known Exploited Vulnerabilities (KEV) Catalog to flag CVE-2026-45659 as now abused in ransomware attacks, not just isolated intrusions. The flaw is a deserialization of untrusted data weakness that lets an attacker with only low privileges execute arbitrary code on unpatched SharePoint servers, and Microsoft has described it as achievable through low-complexity attacks requiring little prior knowledge of the target system.
CISA originally added CVE-2026-45659 to the KEV catalogue on 1 July, giving federal agencies just three days to secure their servers — a compressed timeline that signals how seriously the agency treats deserialization bugs in collaboration platforms. Microsoft itself has not yet updated its own advisory to confirm active exploitation, which means organisations relying solely on vendor status pages for threat intelligence are currently working from an incomplete picture.
Why this matters more for UK on-prem and hybrid estates
The affected products — SharePoint Enterprise Server 2016, SharePoint Server 2019 and SharePoint Server Subscription Edition — are exactly the deployments UK organisations tend to keep on-premises for regulatory, data residency or legacy integration reasons. Cloud-only SharePoint Online tenants sit outside this exposure window, but any hybrid estate with a self-hosted SharePoint farm feeding into wider Microsoft 365 workflows inherits the risk the moment one server is compromised.
This is not a first offence for SharePoint. CISA has flagged 14 actively exploited SharePoint vulnerabilities since November 2021, and eight of those were subsequently weaponised in ransomware campaigns — including the Warlock ransomware incidents that followed last year's on-premises SharePoint attacks, which the UK's National Cyber Security Centre confirmed had hit a limited number of UK organisations directly. The pattern is now well established: exploitation, disclosure, patch, and then a second wave once ransomware operators catch up.
The exposure numbers UK security teams should note
Shadowserver's internet-scanning data currently shows over 8,500 Microsoft SharePoint servers exposed online globally, with more than 200 of them still unpatched against CVE-2026-45659. That residual unpatched population is precisely where ransomware affiliates are hunting, because a low-privilege deserialization bug on an internet-facing server is a far cheaper entry point than phishing or credential stuffing.

How the ransomware attack chain typically plays out
The exploitation pattern CISA and Microsoft have described follows a consistent structure: an internet-facing SharePoint server with the vulnerable deserialization code path, an attacker who needs no special foothold to trigger it, arbitrary code execution on the server, and then a pivot into ransomware deployment across the connected network. Because SharePoint sits deep inside document management and intranet workflows tied to wider Microsoft 365 environments, a single compromised server can expose far more than local files.
Security teams should treat any SharePoint server showing anomalous process activity, unexpected AMSI alerts, or unusual outbound connections as a potential ransomware precursor rather than a routine anomaly. CISA's advisory specifically recommends enabling Windows Antimalware Scan Interface integration for SharePoint web applications and leaning on Microsoft Defender Antivirus detections to catch this behaviour before encryption begins — both of which require configuration effort many organisations have not yet completed.
What UK buyers should do this week
The immediate priority is straightforward: apply Microsoft's latest SharePoint security updates, verify successful installation rather than assuming a deployment succeeded, and monitor affected servers for signs of exploitation that predate the patch. Beyond that, this incident is a useful trigger to review broader resilience posture rather than treating it as a one-off fire drill.
Organisations without a current view of which SharePoint instances are internet-facing, unpatched, or running end-of-support builds should invest in vulnerability management services to close that visibility gap permanently. Because ransomware is the confirmed end state of this exploitation chain, it is also worth stress-testing ransomware protection strategies and ensuring robust backup and disaster recovery arrangements can restore SharePoint content and connected Microsoft 365 data without paying a ransom. Teams that suspect a server may already be compromised should engage expert incident response support rather than patch-and-pray, and any organisation still running out-of-support SharePoint builds should look at third-party maintenance support to keep receiving security fixes.
- 01BleepingComputer — CISA: Microsoft SharePoint flaw now exploited in ransomware attacks · 11 August 2026
- 02NCSC — Active exploitation of vulnerability affecting Microsoft Office SharePoint Server products in the UK · 24 July 2025
- 03Computer Weekly — SharePoint users hit by Warlock ransomware, says Microsoft · 25 July 2025
- 04BleepingComputer — Microsoft SharePoint zero-day exploited in RCE attacks, no patch available · 19 July 2025
- 05The Register — CISA sounds alarm over trio of exploited SharePoint flaws · 15 July 2026
- 06The Hacker News — Hackers exploit SharePoint zero-day · 20 July 2025
