Chors.net
Blog & Insights

Precyzyjna wiedza
o ciemnych systemach.

Ekspercka analiza i studia przypadków dla decydentów. Nawigacja po złożonościach nowoczesnej infrastruktury cyfrowej z niekompromisowymi standardami bezpieczeństwa.

Is your Microsoft SharePoint Server safe from ransomware today? (CVE-2026-45659, CISA KEV)

No — CVE-2026-45659 (CVSS 8.8) is being actively exploited by ransomware gangs and has been in the CISA KEV catalog since July 2, 2026. The flaw is a remote code execution (RCE) via deserialization of untrusted data in Microsoft SharePoint Server — an authenticated user with only the Site Member role (no admin rights) can execute code on the server. A patch has existed since May 2026, yet exploitation persists regardless — organizations that have not patched SharePoint are a real target. In the context of NIS2 art. 21(2), this is a concrete case of failed vulnerability management and patch management.

Key facts

  • CVE-2026-45659 (CVSS 8.8) was added to the CISA Known Exploited Vulnerabilities catalog on July 2, 2026 after confirmation of active exploitation — the flaw was exploited as early as July, even though the patch existed since May.
  • Root cause: RCE via deserialization of untrusted data in SharePoint Server — an authenticated attacker with the Site Member role (without admin privileges) can execute code remotely.
  • Impact: full takeover of the SharePoint server, and for ransomware gangs this is a gateway to escalation, file encryption and extortion.
  • Patches were released by Microsoft in May 2026 for SharePoint Server Subscription Edition and SharePoint Server 2019 — organizations that have not applied the updates are exposed.
  • CISA linked CVE-2026-45659 to a chain of related SharePoint flaws (including CVE-2026-32201, CVE-2026-56164, CVE-2026-58644), indicating deliberate, complex chain attacks rather than isolated exploits.
  • Under NIS2 art. 21(2)(e) (vulnerability management) and art. 21(2)(c) (business continuity) — an unpatched SharePoint is a breach of the risk management obligation.

Decision table: what we know → what it means for B2B / manufacturing → what to do

AreaWhat we knowWhat it means for a B2B / manufacturing firm30-day action90-day action
Patch managementMicrosoft patch available since May 2026; CVE in KEV since 02.07.2026An unpatched SharePoint is an open RCE gateway for ransomwareConfirm SharePoint version and apply the cumulative update immediatelyAutomate patch management (class A); "KEV patch in 14 days" KPI
SharePoint exposureSharePoint often exposed to employees/partners via internet or VPNThe document server is the core of collaboration — ransomware halts the businessRestrict SharePoint access to necessary roles; enforce MFA; audit Site Member rightsSegmentation, reverse proxy, monitoring of farm access
Site Member rightsAttacker needs only the Site Member role (no admin)Over-broad roles lower the barrier for the attackerReview and minimize permissions; remove unused accountsPeriodic permission audits; zero-trust access model to SharePoint
Deserialization / hardeningCISA recommends SharePoint hardening (deserialization protection, IIS machine keys)Deserialization is a recurring vector — worth closing at the sourceApply CISA SharePoint hardening recommendations; rotate IIS keysMonitor deserialization events; EDR rules on the farm
Incident responseCVE actively used by ransomware; exploit works despite the patchYou must know whether an incident already occurred before patchingEnable SharePoint logs to SIEM; retrospect events before the patchIR playbook for SharePoint; backup restore testing
NIS2 / KSC complianceArt. 21(2)(e) vulnerability management; art. 23 incident reportingNeglecting a KEV-listed flaw is a basis for liability over missing patch managementEntry in the risk register; board report on KEV statusCHORS KSC/NIS2 Compliance Program with continuous readiness

Perspective of Marcin Białczyk (CHORS.NET)

SharePoint is for many B2B and manufacturing firms "hidden critical infrastructure": it runs in a farm, serves documents, intranet and approval workflows, yet nobody treats it as a front-line system. The fact that CVE-2026-45659 requires only the Site Member role is operationally decisive — this is not about a full-privilege administrator, but an ordinary project user. That lowers the entry barrier to a level where phishing a single employee account can turn into RCE on the document server. From my operational experience, SharePoint is precisely the system that gets skipped in routine patch management because "it's just intranet" — a costly mistake once ransomware shows up.

At CHORS.NET we see CVE-2026-45659 as a model case for CHORS NIS2/KSC Start or CHORS KSC/NIS2 Compliance Program — not because we patch SharePoint for the client (their team or vendor does), but because the client needs a fast view: is the SharePoint version current, who holds the Site Member role, do logs reach the SIEM, are IIS keys safe. This is an operational audit, not a marketing "security audit". CISA explicitly links this flaw to a chain of related CVEs — patching just one of them is not enough; the whole SharePoint farm must be hardened.

Frequently asked questions

1. Does CVE-2026-45659 require administrator privileges to exploit?

No — an attacker needs only an account with the Site Member role (a site member), without administrator rights. This makes the flaw especially dangerous because the entry barrier is low.

2. Does the patch really exist and does the exploit work despite it?

Yes, Microsoft released updates in May 2026 for SharePoint Server Subscription Edition and SharePoint Server 2019. Yet CISA confirmed active exploitation as early as July — meaning many environments did not apply the patches.

3. What can I do if I cannot patch SharePoint immediately?

Apply temporary mitigations: restrict access to the farm, enforce MFA for all roles, minimize Site Member privileges, and apply CISA SharePoint hardening recommendations with IIS key rotation. This does not waive the obligation to patch at the earliest possible window.

4. Do I have to report this incident to CSIRT NASK / KSC?

The mere existence of the CVE does not require reporting — what requires reporting is the actual incident (confirmed exploit, RCE, encryption). If your SharePoint has been compromised, it is a security incident subject to severity assessment (NIS2 art. 23, KSC art. 11).

How CHORS.NET helps

CHORS.NET supports the technical-operational side: passive exposure assessment, configuration verification, evidence packs and NIS2/KSC readiness support. See: Services, About CHORS.NET and Contact.

Boundaries and assumptions

  • We are not a SOC 24/7 and we do not guarantee detection of every incident.
  • We do not certify NIS2/KSC compliance and we do not issue an independent legal opinion.
  • Results reflect the state at the time of the article (2026-08-13).
  • For legal interpretation of NIS2/KSC, CHORS works with law firms.
  • This material is informational and technical; it is not legal advice and not a guarantee of security.
  • We do not use claims of "full compliance", a "compliance certificate" or "guarantee of detection".

Sources

  1. BleepingComputer — CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
  2. CISA Known Exploited Vulnerabilities Catalog
  3. CISA — Cybersecurity Alerts (SharePoint)
  4. The Hacker News — SharePoint RCE CVE-2026-45659 added to CISA KEV after active exploitation
  5. NVD — CVE-2026-45659 entry (nvd.nist.gov)
  6. CISA — Known Exploited Vulnerabilities Catalog (official)
  7. NIS2 Directive (EU 2022/2555), art. 21(2) and art. 23

Footer

Author: Marcin Białczyk, Founder & Cybersecurity Operator at CHORS.NET Updated: 2026-08-13

CHORS Cryptogram

Minimalistyczny zapis na miesięczne analizy. Surowe dane, trendy audytowe i analiza zero-day prosto na skrzynkę. Zero marketingowego szumu.

Klucz GPG dostępny na życzenie.