A high-severity bug in Microsoft SharePoint that’s been exploited since early July has been abused by ransomware, according to an Aug. 10 update to the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities (KEV) catalog.CISA offered no more information on the nature of the ransomware attack, but the CVSS 8.8 flaw — CVE-2026-45659 — was added to the agency’s KEV on July 1 and patched by Microsoft in late May.In an Aug. 11 statement to SC Media, a Microsoft spokesperson said "We recommend customers apply the May security update CVE-2026-45659 to remain protected. Customers who have already applied the update, or have automatic updates enabled, are already protected and do not need to take further action."Denis Calderone, chief technology officer at Suzu Labs, said this case has the China-linked group Storm-2603 “written all over it.”
“CISA didn't name a threat actor, but Storm-2603 is the only known group that has built a repeatable ransomware operation specifically around on-prem SharePoint deserialization flaws,” said Calderone. “It’s the same vulnerability class and same authentication tier with the same target surface.”Calderone said the Storm-2603 group are also the same China-linked operators who ran the ToolShell campaign against SharePoint last July. Calderone said Microsoft attributes them to China with moderate confidence, while Secureworks says low confidence. However, Calderone said what’s not in dispute is that the group has made on-prem SharePoint their specialty.CISA's entry for CVE-2026-45659 on its KEV catalog.“They exploited the ToolShell zero-day chain in July 2025 to deploy Warlock ransomware, and now they're back doing the same thing with CVE-2026-45659,” said Calderone. “Warlock is built on the leaked LockBit 3.0 builder, but what separates them from typical LockBit affiliates is the zero-day access and the custom AK47 C2 framework they bring to engagements.”Roman Sannikov, global research coordinator at iCounter, said CVE-2026-45659 is a low complexity, minimal privileges required deserialization flaw on an on-premises SharePoint Server.Sannikov said initial access brokers look for that combination: something reliable enough to weaponize at scale and sell, rather than something one group has to painstakingly develop and keep to itself.“No specific ransomware gang has been named yet, and that tracks with how this usually plays out, access gets sold or handed off well before public attribution catches up,” said Sannikov. “Microsoft patched this in May, CISA confirmed active exploitation in July when it went on the KEV, and by August, that exploitation had turned into ransomware.”Sannikov pointed out that’s it’s been three months since the patch existed, and about a month of confirmed active exploitation on top of it, so it’s time for security teams to act.“SharePoint stores an organization's internal documents, permissions, and often its most sensitive records,” said Sannikov. “An unpatched instance at this point usually comes down to a resourcing or prioritization gap inside the organization."
An In-Depth Guide to Ransomware
Get essential knowledge and practical strategies to protect your organization from ransomware attacks.