July 11, 2026 · Alastor InfoSec Team
CVE-2026-45659: SharePoint Server RCE Actively Exploited by Warlock Ransomware — Patch Now
If your organisation runs on-premises Microsoft SharePoint Server and has not applied the May 2026 out-of-band patch, you are likely already in the crosshairs of active ransomware operators. CVE-2026-45659 — a remote code execution vulnerability in SharePoint Server — was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on July 1, 2026, after confirmed evidence of exploitation in the wild. Federal civilian agencies were given until July 4 to patch. For everyone else, there is no safe window remaining.
The Vulnerability: What CVE-2026-45659 Is and Why It's Dangerous
CVE-2026-45659 is a deserialization of untrusted data vulnerability in Microsoft SharePoint Server. It carries a CVSS 3.1 base score of 8.8 — rated High — with a network attack vector, low attack complexity, low privileges required, and no user interaction needed. Those attributes combine to make it particularly dangerous: an attacker does not need to be an administrator or trick a victim into clicking anything. Any authenticated user with SharePoint Site Member permissions can exploit this flaw to execute arbitrary code on the server.
Microsoft's own advisory initially assessed exploitation as "less likely" — a classification that turned out to be wrong. The five-week gap between the May patch release and CISA's July 1 KEV confirmation tells a familiar story: organisations that defer patches because a vendor calls exploitation "less likely" often find themselves deferred right into an active incident.
Affected Versions
The vulnerability affects on-premises SharePoint deployments only. Specifically:
- SharePoint Server Subscription Edition
- SharePoint Server 2019
- SharePoint Enterprise Server 2016
SharePoint Online (Microsoft 365) is not affected. If your organisation has fully migrated to SharePoint Online, you are not exposed by this particular flaw. However, if you run any on-premises SharePoint — whether directly managed or via an MSP — you need to confirm patch status immediately.
What Attackers Are Doing: Storm-2603 and Warlock Ransomware
The exploitation of CVE-2026-45659 has been attributed, at least in part, to Storm-2603, a threat actor that has been active since mid-2025 and has a documented pattern of targeting unpatched on-premises SharePoint servers to deploy Warlock ransomware. Storm-2603's typical attack chain proceeds as follows: exploit the deserialization flaw for initial code execution, establish persistent access via web shells or scheduled tasks, conduct internal reconnaissance to identify high-value file shares and backup systems, and deploy Warlock ransomware across the network after confirming they can maximise encryption coverage.
One incident investigation uncovered two unrelated threat actors operating simultaneously within the same compromised network — both having entered through the same SharePoint vulnerability through independent exploitation. This kind of co-occupation is increasingly common when unpatched internet-facing servers sit exposed for weeks after a patch is available. Ransomware operators monitor for KEV additions and cross-reference them against their reconnaissance data to prioritise targets.
Why "I'll Patch It Next Change Window" Is No Longer Acceptable
The CISA KEV deadline for federal agencies was July 4, 2026. That window has closed. For non-federal organisations, the CISA binding directive technically applies only to federal civilian executive branch agencies — but security practitioners consistently treat KEV additions as a reliable signal that active exploitation is underway and that the window for orderly patching has compressed to days, not weeks.
The practical risk calculus is this: every day an unpatched SharePoint Server is internet-accessible with this vulnerability, any authenticated user — including a contractor, a former employee whose account wasn't deprovisioned, or an attacker who obtained valid credentials through phishing — can execute code on that server. Given how commonly SharePoint is used to store sensitive business documents, M&A materials, HR records, and board communications, the blast radius of a successful exploit followed by ransomware deployment is significant.
Remediation Steps
Step 1: Identify all on-premises SharePoint deployments. If your SharePoint environment is managed by an MSP, contact them immediately and ask for written confirmation of patch status and the date it was applied. Do not assume it has been done.
Step 2: Apply the May 2026 out-of-band patch. Microsoft released the fix via the standard SharePoint cumulative update channel. The specific KB articles vary by version — check the Microsoft Security Update Guide for CVE-2026-45659 and confirm the applicable KB for each server version in your environment.
Step 3: Review authentication logs for anomalies. Because the exploit requires only Site Member authentication, look for unusual behaviour from low-privilege accounts: unexplained API calls, access to administrative functions, PowerShell or .NET execution from the SharePoint application pool, or web shell artifacts (ASPX files written to unusual paths). A five-week exploitation window means some organisations may have already been compromised before they patched.
Step 4: If you find indicators of compromise, assume the network is fully breached. Do not just remove the SharePoint server from scope and move on. Storm-2603 and similar actors establish multiple persistence mechanisms before deploying ransomware. An incident response engagement is warranted if you find evidence of post-exploitation activity.
Step 5: Consider network segmentation for on-premises SharePoint. Internet-facing SharePoint should not have unrestricted lateral movement capability into the rest of your internal network. If it does, a SharePoint compromise is a full network compromise.
How Alastor Helps
Enforster AI scans your external and internal attack surface continuously, including identifying internet-exposed SharePoint instances and flagging known vulnerable software versions against the CISA KEV catalog. If you have an unpatched SharePoint server anywhere in your environment — directly managed, via an MSP, or in a subsidiary network — Enforster will find it and raise a critical finding. Alastor Pulse can validate exploitability through manual penetration testing with a first critical finding in under 6 hours.
If you need an immediate assessment of your SharePoint exposure or suspect you may have been compromised, contact us at [email protected].
CVE-2026-45659 is a textbook example of why "less likely to be exploited" is not a patching strategy — active ransomware deployment through this flaw is confirmed, and every unpatched on-premises SharePoint server is a live target right now.