CISA Flags Actively Exploited SharePoint RCE (CVE‑2026‑45659) Used by Ransomware Gangs
What Happened – The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware groups are actively exploiting a high‑severity remote code execution flaw in Microsoft SharePoint (CVE‑2026‑45659). The vulnerability, a deserialization issue that lets low‑privilege attackers run arbitrary code, has been listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog and is being leveraged in ransomware campaigns since early July.
Why It Matters for Compliance & Audit Readiness
- Demonstrates the risk of unpatched, high‑severity vulnerabilities that can bypass typical access controls – a core scenario SOC 2 expects organizations to detect, remediate, and evidence.
- Highlights the need for continuous vulnerability monitoring and documented patch‑management evidence to satisfy CC6.1 (System Operations) and CC7.1 (Change Management).
- Provides a concrete use‑case for mapping control gaps to audit artifacts, which can be leveraged in a Trust Center or continuous‑compliance dashboard.
Who Is Affected – Enterprises that host on‑premises or cloud‑based Microsoft SharePoint (e.g., technology SaaS providers, professional services firms, government agencies, and any organization using SharePoint for collaboration).
Recommended Actions
- Inventory all SharePoint Server instances (2016, 2019, Subscription Edition) and verify patch level against Microsoft’s July 2026 update.
- Deploy an automated patch‑validation tool that captures installation logs as immutable evidence for SOC 2 auditors.
- Integrate the vulnerability into your continuous‑monitoring platform and map it to the relevant SOC 2 controls (CC6.1, CC7.1).
- Enable AMSI integration and Microsoft Defender AV detections for SharePoint web apps to surface exploitation attempts.
Source: BleepingComputer
Technical Notes – CVE‑2026‑45659 is a deserialization of untrusted data flaw in SharePoint Enterprise Server 2016/2019/Subscription Edition. Exploitation requires low privileges and can be automated with publicly available proof‑of‑concept code. No public CVSS score yet, but Microsoft rates it “high severity.” Source: Microsoft Security Advisory, CISA KEV Catalog