Tag

#CVE-2026-45659

7 stories taggedCVE-2026-45659.

A server room with rows of blinking rack-mounted equipment, one unit highlighted with a red warning indicator among dozens of others still operating normally, d
Vulnerabilities

Ransomware crews are now breaking into SharePoint servers through a May flaw

CISA says criminals are using CVE-2026-45659 to plant ransomware on unpatched Microsoft SharePoint servers. Over 200 remain exposed online.

4 min read
Illustration: a dimly lit server rack in a corporate data centre, blue and amber status LEDs glowing
Vulnerabilities

CISA sounds alarm on SharePoint Server flaws being used to break in right now

The US cyber agency says attackers are chaining three unpatched holes in self-hosted SharePoint to bypass logins, run code and stay hidden. Nearly 10,000 servers sit exposed online.

3 min read
Illustration: a dimly lit server room with rack-mounted enterprise servers, one status LED glowing amber
Vulnerabilities

CISA Warns of Active Attacks on SharePoint Servers, Urges Immediate Patching

Three flaws are being chained to break into on-premises SharePoint, steal cryptographic keys, and plant malware. Two more just disclosed could be next.

3 min read
Illustration: a dimly lit government server room, rows of racks with faint blue and amber status LEDs
Policy & Regulation

CISA orders federal agencies to patch SharePoint flaw by Saturday as attacks begin

A newly exploited Microsoft SharePoint bug lands in CISA's Known Exploited Vulnerabilities Catalog, triggering a three-day patching clock under Binding Operational Directive 26-04.

3 min read
Illustration for the story: CISA: Attackers Are Actively Exploiting a Dangerous Flaw in Microsoft SharePoint
Vulnerabilities

CISA: Attackers Are Actively Exploiting a Dangerous Flaw in Microsoft SharePoint

A vulnerability in SharePoint, Microsoft's widely used workplace collaboration platform, lets criminals run malicious code on company servers. Patches have been available since late May. Many organisations haven't applied them.

3 min read
Illustration: a dimly lit enterprise server room with rack-mounted servers glowing amber
Vulnerabilities

CISA Flags SharePoint Deserialization Bug CVE-2026-45659 as Actively Exploited

The RCE flaw joins KEV with a three-week federal patch deadline. Attribution details remain thin.

3 min read
Illustration: A digital shield protecting a SharePoint server
Vulnerabilities

SharePoint's latest RCE bug hands attackers the keys with no extra paperwork

CVE-2026-45659 is a deserialization flaw that doesn't ask for much, and that's exactly why Microsoft is shipping fixes across every supported SharePoint Server build.

2 min read
© 2026 Threat Vectr