Web_Logo
Remote Support
Security Alert: SharePoint Server Flaw Under Active Attack
Home » Security Alerts  »  Security Alert: SharePoint Server Flaw Under Active Attack

Security Alert: SharePoint Server Flaw Under Active Attack

The US Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that a serious flaw in Microsoft SharePoint Server is being actively exploited by attackers, including groups known for deploying ransomware.

  • What it is: A remote code execution vulnerability (CVE-2026-45659) in on-premises SharePoint Server that lets an attacker with basic site access run malicious code on the server.
  • Who is affected: Organisations running SharePoint Server Subscription Edition, SharePoint Server 2019, or SharePoint Enterprise Server 2016 on their own infrastructure. SharePoint Online (Microsoft 365) is not affected.
  • What the risk is: Attackers exploiting this flaw have been linked to ransomware deployment, meaning a successful attack could lead to data theft and full network compromise.
  • What action is needed: Microsoft released a fix for this vulnerability in May 2026. Any business still running an affected on-premises SharePoint Server should confirm the patch has been applied immediately.

If you are unsure whether your SharePoint environment is patched, we recommend checking with your IT provider today rather than waiting for the next scheduled maintenance window.

Source: The Hacker News