ON
← Back to feed
Patch released in May: Ransomware attacks Microsoft Sharepoint
Germany🏛️ PoliticsCenter12 days ago

Patch released in May: Ransomware attacks Microsoft Sharepoint

Ein schweres Sicherheitsleck in Microsoft SharePoint, bekannt als CVE-2026-45659, wird von Angreifern genutzt, um Ransomware einzusetzen. Die Lücke ermöglicht es Angreifern, Schadsoftware einzuschleusen und auszuführen, ohne besondere Rechte. Microsoft veröffentlichte im Mai Sicherheitsupdates, doch Scans zeigten, dass über 200 ungepatchte SharePoint-Server weltweit online sind, wobei Deutschland, Österreich und die Schweiz jeweils eine kleine Zahl aufweisen. CISA hat die Lücke im 'Known Exploited Vulnerabilities Catalogue' als aktiv genutzt eingestuft, während Microsoft die Ausnutzung in der Wildnis noch nicht bestätigt hat. Die Schwachstelle resultiert aus der Deserialisierung unsicherer Daten und ist leicht zu exploitieren, was Microsoft jedoch als unwahrscheinlich eingeschätzt hatte.

Administrators managing Microsoft SharePoint Server within their infrastructure should verify whether they have installed the May updates, according to a recent alert. A high-risk vulnerability in SharePoint, identified as CVE-2026-45659 with a CVSS score of 8.8 and a risk rating of “high,” has been actively exploited in ransomware campaigns. This information was published in the Known Exploited Vulnerabilities Catalogue by the U.S. Cybersecurity & Infrastructure Security Agency (CISA) on Tuesday. The vulnerability allows attackers to inject and execute malicious code, making it a critical concern for organizations using affected systems. Microsoft made available security patches for SharePoint Enterprise Server 2016, SharePoint Server 2019, and the Server Subscription Edition in late May. These updates address the specific flaw that enables remote code execution through deserialization of untrusted data. However, despite these efforts, scans conducted by the Shadowserver Foundation revealed over 200 publicly accessible and unpatched SharePoint servers on the internet. Of these, approximately half are located in the United States, around a quarter in Europe, and a dozen in Germany. Austria and Switzerland show lower numbers, though additional cases may exist that were not detected during the scan. As of early June, Shadowserver had previously recorded nearly 1,100 unpatched instances of SharePoint online. The vulnerability exploits a flaw in how SharePoint processes serialized data, allowing attackers to run arbitrary code without requiring elevated privileges. This means that even unauthorized users could potentially exploit the weakness remotely, including from the internet. The method involves injecting malicious payloads into serialized objects, which are then deserialized by the application, leading to code execution. Such attacks are considered low complexity because attackers need minimal prior knowledge about the target system to carry them out. Microsoft initially assessed the likelihood of exploitation as relatively low, assigning a CVSS Temporal Score of 7.7 in May. Despite this, the active use of the vulnerability in real-world ransomware attacks suggests that the threat level has increased significantly. The CISA update confirms that the vulnerability is being used in ongoing cybercriminal activities, emphasizing the urgency for administrators to apply the necessary patches. Security experts warn that the widespread availability of unpatched SharePoint servers creates a large attack surface for potential breaches. The number of vulnerable systems still online indicates a lack of awareness or enforcement of patch management protocols among some organizations. While Microsoft has taken steps to provide fixes, the continued presence of exposed systems highlights gaps in cybersecurity practices. The situation underscores the importance of regular software updates and proactive security measures. Organizations running SharePoint must ensure all systems are up to date with the latest security patches. In addition, network monitoring and intrusion detection systems can help identify and respond to suspicious activity before it leads to a breach. As ransomware attacks continue to evolve, staying ahead of emerging threats requires constant vigilance and adherence to best practices in information security.

Go to the primary sources (2)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenterFactual 93Objective 8512 days ago
Patch released in May: Ransomware attacks Microsoft Sharepoint

Ein schweres Sicherheitsleck in Microsoft SharePoint, bekannt als CVE-2026-45659, wird von Angreifern genutzt, um Ransomware einzusetzen. Die Lücke ermöglicht es Angreifern, Schadsoftware einzuschleusen und auszuführen, ohne besondere Rechte. Microsoft veröffentlichte im Mai Sicherheitsupdates, doch Scans zeigten, dass über 200 ungepatchte SharePoint-Server weltweit online sind, wobei Deutschland, Österreich und die Schweiz jeweils eine kleine Zahl aufweisen. CISA hat die Lücke im 'Known Exploited Vulnerabilities Catalogue' als aktiv genutzt eingestuft, während Microsoft die Ausnutzung in der Wildnis noch nicht bestätigt hat. Die Schwachstelle resultiert aus der Deserialisierung unsicherer Daten und ist leicht zu exploitieren, was Microsoft jedoch als unwahrscheinlich eingeschätzt hatte.

Bias read (Center): Die Berichterstattung bleibt sachlich und konzentriert sich auf technische Aspekte der Sicherheitslücke. Es wird keine politische Haltung oder parteiliche Agenda gezeigt. Die Quellen werden neutral zitiert, und es wird keine emotionale oder ideologische Bewertung der Situation vorgenommen.

Why factuality (93): The article accurately reports the CVE-2026-45659 vulnerability in Microsoft SharePoint Server, citing the CISA KEV catalog as the source. It mentions the vulnerability's classification as high risk (CVSS 8.8), its exploitation in ransomware campaigns, and the availability of patches from May. The a

Why objectivity (85): The article presents the facts neutrally but includes some interpretive elements such as 'hochriskante' (high-risk) and 'Ransomware-Kampagnen' (ransomware campaigns), which could imply a stronger emphasis on the threat than strictly necessary. While it cites sources like CISA and Shadowserver, it al

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories