HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

CISA Flags Actively Exploited SharePoint RCE (CVE‑2026‑45659) Used by Ransomware Gangs

CISA has added Microsoft SharePoint CVE‑2026‑45659 to its KEV catalog after confirming ransomware groups are exploiting the remote‑code execution flaw. Organizations must prove they patch promptly and retain evidence to satisfy SOC 2 audit requirements.

LiveThreat™ Intelligence · 📅 August 12, 2026· 📰 bleepingcomputer.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

CISA Flags Actively Exploited SharePoint RCE (CVE‑2026‑45659) Used by Ransomware Gangs

What Happened – The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware groups are actively exploiting a high‑severity remote code execution flaw in Microsoft SharePoint (CVE‑2026‑45659). The vulnerability, a deserialization issue that lets low‑privilege attackers run arbitrary code, has been listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog and is being leveraged in ransomware campaigns since early July.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates the risk of unpatched, high‑severity vulnerabilities that can bypass typical access controls – a core scenario SOC 2 expects organizations to detect, remediate, and evidence.
  • Highlights the need for continuous vulnerability monitoring and documented patch‑management evidence to satisfy CC6.1 (System Operations) and CC7.1 (Change Management).
  • Provides a concrete use‑case for mapping control gaps to audit artifacts, which can be leveraged in a Trust Center or continuous‑compliance dashboard.

Who Is Affected – Enterprises that host on‑premises or cloud‑based Microsoft SharePoint (e.g., technology SaaS providers, professional services firms, government agencies, and any organization using SharePoint for collaboration).

Recommended Actions

  • Inventory all SharePoint Server instances (2016, 2019, Subscription Edition) and verify patch level against Microsoft’s July 2026 update.
  • Deploy an automated patch‑validation tool that captures installation logs as immutable evidence for SOC 2 auditors.
  • Integrate the vulnerability into your continuous‑monitoring platform and map it to the relevant SOC 2 controls (CC6.1, CC7.1).
  • Enable AMSI integration and Microsoft Defender AV detections for SharePoint web apps to surface exploitation attempts.

Source: BleepingComputer

Technical Notes – CVE‑2026‑45659 is a deserialization of untrusted data flaw in SharePoint Enterprise Server 2016/2019/Subscription Edition. Exploitation requires low privileges and can be automated with publicly available proof‑of‑concept code. No public CVSS score yet, but Microsoft rates it “high severity.” Source: Microsoft Security Advisory, CISA KEV Catalog

📰 Original Source
https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-flaw-now-exploited-in-ransomware-attacks/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →