This just escalated. If your organization or your customers operate on-premises Microsoft SharePoint, this deserves immediate attention.
On August 11, CISA confirmed that attackers are now using an actively exploited Microsoft SharePoint vulnerability in ransomware campaigns. This is no longer simply a vulnerability-management issue. It is an active ransomware threat.
For network defenders, MSPs, IT leaders, and business owners, the message is simple: patch immediately, investigate for compromise, and do not assume detection alone will protect the environment.
The vulnerability, CVE-2026-45659, affects on-premises Microsoft SharePoint Server. According to the BleepingComputer report, attackers with relatively low privileges can exploit the flaw to remotely execute code on an unpatched SharePoint server. The attack is considered low complexity and does not require user interaction.
Microsoft issued security updates in May, and CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog in July. Now the situation has escalated again. CISA has confirmed the vulnerability is being used in ransomware campaigns.
Shadowserver is tracking more than 8,500 internet-exposed SharePoint servers, including more than 200 that remained unpatched against this vulnerability as of August 11.
That makes this an immediate defensive priority.
A SharePoint server can sit close to extremely valuable business resources: documents, users, credentials, applications, servers, and other connected systems.
Successful remote code execution can give an attacker the foothold needed to move from vulnerability exploitation into credential theft, lateral movement, security-tool tampering, data theft, and ultimately ransomware.
We have seen this pattern before. During earlier SharePoint exploitation, Microsoft documented attackers abusing legitimate Windows processes, stealing credentials, moving laterally through tools such as WMI and PsExec, disabling Defender protections, manipulating Group Policy, and ultimately deploying ransomware.
This is exactly why vulnerability exploitation cannot be treated as an isolated server problem.
The business consequences can include operational downtime, lost productivity, recovery expenses, reputational damage, regulatory exposure, and customer disruption.
IBM's 2026 Cost of a Data Breach Report puts the global average cost of a breach at $4.99 million, with the U.S. average reaching $11.5 million. IBM also reports that increases in detection, escalation, and lost-business costs accounted for 63% of this year's average breach-cost increase.
And according to Verizon's 2026 Data Breach Investigations Report, ransomware is now involved in 48% of breaches.
Yes.
In our August 5 podcast, Cybersecurity vs. Invisible AI Attacks: Why MSPs Need Prevention Before Detection, we discussed why the security model has to evolve beyond waiting for malicious behavior to be identified after execution begins.
This SharePoint situation reinforces that point.
Attackers increasingly exploit vulnerabilities, abuse valid credentials, operate through legitimate Windows tools, live off the land, interfere with security products, and move quickly once inside.
Detect and Respond is still important. It just cannot be the entire strategy.
When ransomware operators are moving from an exposed vulnerability toward execution, credential access, lateral movement, and encryption, organizations need controls capable of stopping unauthorized behavior even when detection misses the initial activity.
The objective should be to reduce what an attacker can actually accomplish after gaining a foothold.
An Isolation and Containment model restricts unauthorized execution, places guardrails around trusted applications, limits attacker movement, reduces the blast radius of a compromise, and works to prevent destructive activity such as ransomware encryption before it begins.
This is particularly important with living-off-the-land attacks where attackers may use legitimate Windows applications and processes rather than introducing easily identifiable malware.
AppGuard is a proven endpoint protection solution with a 10-year track record focused on prevention through Isolation and Containment.
It should not replace patch management, EDR, MDR, backups, or incident response. The objective is to add another defensive layer so that failure of one security control does not automatically become a business-ending incident.
If you operate Microsoft SharePoint Server on-premises:
CISA specifically recommends monitoring affected servers for exploitation, applying Microsoft's latest patches, verifying installation, and shortening patching cycles.
The most important takeaway is not simply that another SharePoint vulnerability exists.
Attackers are already using it for ransomware.
The time to determine whether your defenses can contain an attacker after initial access is before that attacker reaches your network.
Business owners who want to better understand how prevention-first security can stop attacks before damage occurs should talk with CHIPS about how AppGuard can help prevent incidents like this through Isolation and Containment.