SharePoint Flaw Now Used in Ransomware Attacks: Act Now
A critical vulnerability in Microsoft SharePoint Server – patched back in May 2026 – is now being actively used in ransomware campaigns. If your SharePoint environment has not been updated since the spring, you may be exposed right now.
What has happened
In May 2026, Microsoft released an out-of-band security update to fix CVE-2026-45659, a high-severity remote code execution vulnerability in SharePoint Server. “Out-of-band” means it was released outside Microsoft’s normal monthly patching cycle – which is significant, because businesses that only apply the standard monthly updates may have missed it.
Patch Tuesday is the name for Microsoft’s regular monthly security updates, released on the second Tuesday of every month. Out-of-band releases go out whenever a flaw is serious enough not to wait. CVE-2026-45659 was considered serious enough.
The vulnerability scores 8.8 out of 10 on the CVSS severity scale and works by exploiting how SharePoint handles certain types of incoming data. An authenticated attacker – someone with at least basic Site Member access – can use it to run arbitrary code directly on the SharePoint server.
On 1 July 2026, the US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-45659 to its Known Exploited Vulnerabilities catalogue. This catalogue only lists flaws that are confirmed to be actively exploited – not theoretically risky, but actually being used in real attacks. Since that listing, security researchers have observed multiple ransomware groups incorporating this vulnerability into their attack chains.
Why it matters to your business
SharePoint Server – whether deployed on-premises or in a hybrid setup alongside Microsoft 365 – is a core document management and collaboration platform for many businesses. A successful exploit gives an attacker code execution at the server level. In practice, that means they can:
- Read and exfiltrate sensitive documents stored on SharePoint
- Deploy ransomware or other malware on the server
- Move laterally through your network from the compromised server
The requirement for a valid user account does raise the bar slightly. But ransomware groups routinely obtain credentials in advance through phishing, password reuse, or purchasing stolen logins from data breach markets. “Needs a valid login” is not a reliable barrier when those logins are readily available.
What makes out-of-band patches easy to miss
Microsoft’s regular Patch Tuesday cycle is well understood, and most IT teams schedule those updates monthly. But when a patch arrives outside that cycle, it demands its own attention – and in busy environments, it can slip through the net.
That is what makes CVE-2026-45659 particularly important to check. If your patching process is primarily calendar-driven around Patch Tuesday, the May out-of-band release may not have been picked up at the time. Combine that with a month of confirmed active exploitation by ransomware groups, and the risk of remaining unpatched is very real.
What we have already done for managed clients
If you are a managed client of System Force IT, you do not need to take any action. We apply security patches – including out-of-band releases – as part of our managed IT services. We also monitor CISA’s Known Exploited Vulnerabilities catalogue and take proactive steps when a vulnerability moves from theoretical risk to confirmed exploitation in the wild.
What to check if you are not a managed client
If you manage your own IT or use a different provider, here is what to do now:
- Check your SharePoint patch history. The fix for CVE-2026-45659 should appear in your Windows Update or WSUS history for May 2026. If it is missing, apply it immediately from Microsoft’s Security Update Guide.
- Audit SharePoint access. Review who holds Site Member or higher permissions. Remove any accounts that no longer need them.
- Enable MFA. Multi-factor authentication should be enforced for all accounts that can access SharePoint remotely. Cyber Essentials certification includes MFA requirements and gives businesses a clear baseline to work from.
- Review your patching process. If your current IT arrangement does not pick up out-of-band security releases promptly, that is a gap in your cyber security posture worth addressing urgently.
What to do next
If you are running SharePoint Server – on-premises or hybrid – and are not certain whether CVE-2026-45659 has been patched in your environment, do not leave it to chance. Get in touch or call 01452 701355. We can carry out a quick check and confirm whether you are protected – and if not, get you sorted without delay.
Stay one step ahead of the threats
Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.
Get the free weekly briefing →


