Skip to main content

Microsoft SharePoint Server Deserialization Flaw Now Actively Exploited in Ransomware Campaigns (CVE-2026-45659)

Scope: Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016 (On-Premises Only)

Severity: Red

CISA confirmed today, August 11, 2026, that ransomware gangs are actively abusing CVE-2026-45659, a high-severity deserialization of untrusted data vulnerability in Microsoft SharePoint Server, after adding it to the Known Exploited Vulnerabilities catalog in July following confirmed exploitation by Storm-2603, a threat actor known for deploying Warlock ransomware through SharePoint exploitation paths since mid-2025. Any authenticated attacker with a minimum of Site Member permissions can trigger the flaw without any user interaction or elevated privileges, executing arbitrary code on the SharePoint server and establishing persistent web shell access for lateral movement, data exfiltration, and ransomware staging. SharePoint is the primary intranet and document management platform across Ugandan government and enterprise environments, making unpatched on-premises farms an immediate priority. Organizations must apply Microsoft's May 2026 cumulative update immediately, enable AMSI in Full Mode, rotate SharePoint ASP.NET machine keys, restart IIS after patching, and monitor SharePoint ULS and IIS logs for unauthorized POST requests as indicators of prior compromise.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.