Capital Cyber News
Reporting for United States defense contractors and small business KEV catalog 2026.08.14

Threats and Vulnerabilities

SharePoint Server Under Active Exploitation

SharePoint servers running on-premises now face a new threat. On July 1, 2026, CVE-2026-45659 appeared in the CISA Known Exploited Vulnerabilities Catalog, with clear ties to ransomware campaigns. This isn’t simply a technical detail to track; for businesses handling Controlled Unclassified Information, the risk goes straight to daily operations and compliance.

What is the new SharePoint vulnerability CVE-2026-45659?

CVE-2026-45659 is described as a Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability. According to the CISA Known Exploited Vulnerabilities Catalog, this vulnerability is actively being exploited by ransomware operators. It was officially added to the catalog on July 1, 2026, and is marked as being used in known ransomware campaigns.

SharePoint servers are widely used for collaboration and document management. For many organizations, especially defense contractors and those handling CUI, SharePoint often stores sensitive project files, contracts, and compliance documentation. A vulnerability in this platform can expose your most critical business information.

Why are on-premises SharePoint servers a scoping problem?

On-premises collaboration servers like SharePoint often fall into a blind spot for both security and compliance. You may have cloud systems and endpoints under tight control, but on-premises servers can be overlooked during risk assessments and compliance scoping. This is especially problematic if you store or process CUI or other regulated data on these systems.

If your SharePoint server is on-premises and holds CUI, it is within scope for frameworks like NIST 800-171 and CMMC. Every control that applies to your environment also applies to that server. That means patching, access control, monitoring, and incident response requirements all extend to this system. Failing to include on-premises servers in your compliance program can create gaps that put your contracts and reputation at risk.

How does ransomware exploit SharePoint vulnerabilities?

The CISA Known Exploited Vulnerabilities Catalog lists 349 entries with known ransomware campaign use, including CVE-2026-45659. Attackers target vulnerabilities like this one to gain access to internal systems, encrypt data, and demand payment. Since SharePoint servers often house important business and compliance information, a ransomware attack can disrupt operations and lead to data loss or exposure.

The fact that CVE-2026-45659 is flagged for ransomware use means threat actors are actively targeting unpatched servers. If your SharePoint server is internet-facing or accessible from outside your core network, the risk is even greater.

What should you do if you have on-premises SharePoint?

First, determine whether your organization is running on-premises SharePoint servers. If so, check your current patch status and review whether CVE-2026-45659 has been addressed by your team or your IT provider. Strong patch management is critical: vulnerabilities being exploited in ransomware campaigns are high priorities for remediation.

Second, include your SharePoint server in your compliance scoping and risk assessments. If you handle CUI or are subject to NIST 800-171 or CMMC requirements, ensure your controls are implemented and enforced on this server. That includes more than patching but also access controls, logging, and backup procedures.

Finally, consider whether on-premises collaboration systems are still the right choice for your business. Many organizations are moving to cloud-hosted collaboration platforms that often offer more frequent security updates and built-in compliance features.

How does this SharePoint vulnerability compare to other recent threats?

CVE-2026-45659 is one of 181 vulnerabilities added to the CISA Known Exploited Vulnerabilities Catalog since January 1, 2026. Of the 1665 total entries, 349 are flagged for known ransomware campaign use. Recent vulnerabilities with ransomware use have affected a wide range of products, including SonicWall appliances, Microsoft Exchange Server, and Cisco Secure Firewall Management Center. The presence of multiple SharePoint vulnerabilities, some with known ransomware use and others with unknown status, highlights the ongoing risk to collaboration platforms.

Common questions

Is this SharePoint vulnerability only a risk for internet-facing servers?

No. While internet-facing servers are at greater risk, any unpatched SharePoint server can be exploited if attackers gain access to your internal network. Always include all servers in your patch management process.

Does CVE-2026-45659 only affect organizations with CUI?

No. Any organization using SharePoint Server is at risk if the vulnerability is not patched. However, the impact is greater for organizations handling CUI or regulated data due to compliance obligations.

How can I find out if my SharePoint server is vulnerable?

Consult your IT provider or internal IT team to check patch status and review recent updates. Reference the CISA Known Exploited Vulnerabilities Catalog for guidance on which vulnerabilities require immediate action.

What’s the next step for defense contractors?

If you are a defense contractor or handle CUI and are concerned about NIST 800-171 or CMMC readiness, you can apply for the Cyber Grants Alliance CMMC Gap Assessment Grant. This is an in kind grant delivered as services, covering all 110 controls for qualifying defense contractors. Learn more and apply at https://cybergrantsalliance.org/cmmc-gap-assessment-grant/.

Staying current with known exploited vulnerabilities like CVE-2026-45659 protects your business and your contracts. Review your SharePoint deployment, update your patch management, and make sure your collaboration servers are always included in your security and compliance program.

More on Threats

Threats · 4 min When Your IT Provider Is the Attack Path

Learn how the recent CVE-2026-18556 in N-able N-central highlights the risks of MSP supply chain attack and what you should ask your IT provider.