The images in this article were generated with artificial intelligence. How we publish
The US Agency for Infrastructure and Cybersecurity. US (CISA) has recently included in its catalogue of known and exploited vulnerabilities (KEV) a high-gravity failure affecting Microsoft SharePoint servers: this is the failure recorded as CVE-2026-45659, a remote code execution vulnerability resulting from the deerialization of unreliable data. Although Microsoft corrected it in May 2026 for SharePoint Server Subscription Edition, SharePoint Server 2019 and SharePoint Enterprise Server 2016, the emergence of active operation indicators has forced security teams to accelerate their response, and the deadline recommended by CISA for federal government entities is to apply the patches before 4 July 2026. More general information on the KEV list is available on the CISA website: https: / / www.cisa.gov / knowledge-exploited-vulnerabilities-catalog.
From a technical point of view, vulnerability allows an authenticated attacker with minimum site member privileges to run code on the SharePoint server without administrative credentials. This makes SharePoint on-premises servers particularly attractive because many organizations retain local bodies that integrate automated critical content and workflows and that, by default, expose authentication mechanisms that can be coopted by phishing, filtered credentials or chained exploitation of other failures.

The Microsoft evaluation described the probability of exploitation as "less likely," but the inclusion in the CISA catalogue by evidence of real abuse shows a common tension between internal risk assessments and field observations. This discrepancy is relevant to security officials: if there is any indication of exploitation, caution requires prioritizing immediate mitigation, regardless of probability labels.
This case comes in a broader context of complex attacks where, according to Microsoft research, actors like Storm-2603 have exploited on-premises servers - including vectors against SharePoint - to deploy ansomware and maintain prolonged access. The attackers combine legitimate management and telemetry tools (e.g. Velociraptor), tunnels through cloud services, and remote access channels such as Zoho Assist or SSH managed by IDEs, as well as privilege climbing techniques and driver handling to evade defenses. Microsoft documents this type of activity on its security blog: https: / / www.microsoft.com / security / blog /.
The operational lesson is clear: an apparently unique incident (a ransomware attack) can hide multiple actors and intrusion chains, which complicates containment and mediation if only the symptom is addressed. Response teams should assume the possibility of parallel activity, seek traces of lateral movements and persistent access, and not limit the investigation to the initial sample of the incident.
In practical and urgent terms, the recommendation for administrators is to prioritize the application of patches published by Microsoft in all environments that run the affected editions of SharePoint. If it is not possible for operational limitations to apply the update immediately, it is appropriate to block or restrict access to SharePoint management interfaces and services from public networks, to strengthen multi-factor authentication controls, to review and minimize site member permissions, and to segment the network so that critical servers do not have direct access routes from workstations or Internet exits.

For detection and response, signs of abuse associated with the above tactics should be sought: creation of unusual local or domain accounts, installation of remote management tools or tunnels, records showing atypical requests to configuration files (e.g. web.config or win.ini) and typical DLL side-rolling patterns or running unexpected binaries. Correlate EDR events, proxy / reverse proxy and identity telemetry helps to distinguish legitimate activity from malicious; technical details on vulnerability can be found in the NVD base: https: / / nvd.nist.gov / vuln / detail / CVE-2026-45659.
In the medium and long term, it is appropriate to rethink the exposure of critical business services in on-premises: maintain frequent patch cycles, strengthen account control with privileges, monitor encrypted outgoing connections that can be tunnels and validate the integrity of third-party drivers and software. In addition, establishing response processes that consider scenarios with multiple simultaneous adversaries reduces the likelihood of underestimating the scope of an intrusion and facilitates complete containment.
If your organization detects suspicious activity or signs compatible with the exploitation of this vulnerability, it is wise to activate your incident response plan, take immediate containment measures and, if appropriate, seek support from a specialized forensic response team. The official references of CISA and Microsoft, in addition to public vulnerability pages, are useful starting points for testing and prioritizing: review the guidelines in CISA KEV and Microsoft information on Microsoft Security.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...