UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber security

SharePoint RCE Now Fuels Ransomware: UK Patch Priority 2026

London · Servnet News Desk · IT infrastructure analysis3 min read
Share

CISA has confirmed that ransomware gangs are now actively exploiting CVE-2026-45659, a high-severity Microsoft SharePoint remote code execution flaw first flagged as exploited in early July. For UK enterprises still running on-premises or hybrid SharePoint, this is the patch to prioritise above everything else this week.

SharePoint exposure vs unpatched servers (August 2026)
8500 servers6375 servers4250 servers2125 servers0 servers8500 serversExposed online200 serversUnpatched vs CVE-2026-4565…SharePoint servers
View the data behind this chart
SharePoint exposure vs unpatched servers (August 2026)
Exposed onlineUnpatched vs CVE-2026-4565…
SharePoint serversservers8500servers200

What CISA confirmed today

On 11 August, CISA updated its Known Exploited Vulnerabilities (KEV) Catalog to flag CVE-2026-45659 as now abused in ransomware attacks, not just isolated intrusions. The flaw is a deserialization of untrusted data weakness that lets an attacker with only low privileges execute arbitrary code on unpatched SharePoint servers, and Microsoft has described it as achievable through low-complexity attacks requiring little prior knowledge of the target system.

CISA originally added CVE-2026-45659 to the KEV catalogue on 1 July, giving federal agencies just three days to secure their servers — a compressed timeline that signals how seriously the agency treats deserialization bugs in collaboration platforms. Microsoft itself has not yet updated its own advisory to confirm active exploitation, which means organisations relying solely on vendor status pages for threat intelligence are currently working from an incomplete picture.

Why this matters more for UK on-prem and hybrid estates

The affected products — SharePoint Enterprise Server 2016, SharePoint Server 2019 and SharePoint Server Subscription Edition — are exactly the deployments UK organisations tend to keep on-premises for regulatory, data residency or legacy integration reasons. Cloud-only SharePoint Online tenants sit outside this exposure window, but any hybrid estate with a self-hosted SharePoint farm feeding into wider Microsoft 365 workflows inherits the risk the moment one server is compromised.

This is not a first offence for SharePoint. CISA has flagged 14 actively exploited SharePoint vulnerabilities since November 2021, and eight of those were subsequently weaponised in ransomware campaigns — including the Warlock ransomware incidents that followed last year's on-premises SharePoint attacks, which the UK's National Cyber Security Centre confirmed had hit a limited number of UK organisations directly. The pattern is now well established: exploitation, disclosure, patch, and then a second wave once ransomware operators catch up.

The exposure numbers UK security teams should note

Shadowserver's internet-scanning data currently shows over 8,500 Microsoft SharePoint servers exposed online globally, with more than 200 of them still unpatched against CVE-2026-45659. That residual unpatched population is precisely where ransomware affiliates are hunting, because a low-privilege deserialization bug on an internet-facing server is a far cheaper entry point than phishing or credential stuffing.

Illustration: SharePoint RCE Now Fuels Ransomware: UK Patch Priority 2026

How the ransomware attack chain typically plays out

The exploitation pattern CISA and Microsoft have described follows a consistent structure: an internet-facing SharePoint server with the vulnerable deserialization code path, an attacker who needs no special foothold to trigger it, arbitrary code execution on the server, and then a pivot into ransomware deployment across the connected network. Because SharePoint sits deep inside document management and intranet workflows tied to wider Microsoft 365 environments, a single compromised server can expose far more than local files.

Security teams should treat any SharePoint server showing anomalous process activity, unexpected AMSI alerts, or unusual outbound connections as a potential ransomware precursor rather than a routine anomaly. CISA's advisory specifically recommends enabling Windows Antimalware Scan Interface integration for SharePoint web applications and leaning on Microsoft Defender Antivirus detections to catch this behaviour before encryption begins — both of which require configuration effort many organisations have not yet completed.

What UK buyers should do this week

The immediate priority is straightforward: apply Microsoft's latest SharePoint security updates, verify successful installation rather than assuming a deployment succeeded, and monitor affected servers for signs of exploitation that predate the patch. Beyond that, this incident is a useful trigger to review broader resilience posture rather than treating it as a one-off fire drill.

Organisations without a current view of which SharePoint instances are internet-facing, unpatched, or running end-of-support builds should invest in vulnerability management services to close that visibility gap permanently. Because ransomware is the confirmed end state of this exploitation chain, it is also worth stress-testing ransomware protection strategies and ensuring robust backup and disaster recovery arrangements can restore SharePoint content and connected Microsoft 365 data without paying a ransom. Teams that suspect a server may already be compromised should engage expert incident response support rather than patch-and-pray, and any organisation still running out-of-support SharePoint builds should look at third-party maintenance support to keep receiving security fixes.

Share
Key takeaways
  • CISA confirmed on 11 August that ransomware gangs are actively exploiting CVE-2026-45659, a high-severity SharePoint deserialization RCE flaw.
  • The vulnerability affects SharePoint Enterprise Server 2016, SharePoint Server 2019 and SharePoint Server Subscription Edition — on-prem and hybrid deployments only.
  • Shadowserver counts over 8,500 exposed SharePoint servers globally, with more than 200 still unpatched against this specific CVE.
  • Eight of the 14 actively exploited SharePoint vulnerabilities since 2021 have gone on to be used in ransomware attacks, making rapid patching non-negotiable.
Frequently asked

FAQs — SharePoint RCE Now Fuels Ransomware

Is CVE-2026-45659 confirmed as ransomware-exploited by Microsoft?

CISA has flagged it as ransomware-exploited via its KEV Catalog update, but Microsoft has not yet updated its own advisory to confirm active exploitation, so organisations should not wait for vendor confirmation before patching.

Does this affect SharePoint Online (cloud-only) tenants?

No. The affected products named are SharePoint Enterprise Server 2016, SharePoint Server 2019 and SharePoint Server Subscription Edition, all on-premises or hybrid deployments; cloud-only SharePoint Online is outside this exposure.

How many SharePoint servers are still vulnerable?

Shadowserver's internet-scanning data shows over 8,500 SharePoint servers exposed online, with more than 200 unpatched against CVE-2026-45659 specifically.

What should UK security teams do beyond patching?

CISA recommends monitoring for exploitation signs, enabling AMSI integration for SharePoint web applications, and using Microsoft Defender Antivirus detections; organisations should also review managed detection & response coverage for on-prem servers.

Related

Turning this into a buying decision?

One conversation with an engineer who's specced this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111