Threat reportVulnerabilityTL-2026-1061
CVE-2026-45659: SharePoint Deserialization RCE Added to CISA KEV Amid Storm-2603 Exploitation
CVE-2026-45659 (TL-2026-1061), also tracked as ToolShell (related 2025 campaign), is a high-severity software vulnerability scored CVSS 8.8, first published 2026-07-02. It is attributed to Storm-2603 (China) with medium confidence, affects Microsoft SharePoint Server Subscription Edition, references 5 CVEs (CVE-2026-45659, CVE-2025-49704, CVE-2025-49706), maps to 28 MITRE ATT&CK techniques (T1003.001, T1016, T1021), and is covered by 9 detection rules and 30 indicators of compromise.
- CVSS
- 8.8/10High
- CVEs
- 5Referenced vulnerabilities
- Techniques
- 28MITRE ATT&CK
- Actors
- 1Storm-2603
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 30Indicators of compromise
Key facts for TL-2026-1061
- Threat ID
- TL-2026-1061
- Also known as
- ToolShell (related 2025 campaign), Project AK47
- Severity
- HIGH
- CVSS
- 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution
- Storm-2603
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- FINANCIAL
- Target sectors
- government administration, criticalinfrastructure, professionalservices, finance, manufacturing, education
- Target regions
- North America, Asia-Pacific, Latin America, Europe
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in CVE-2026-45659
Malware and tooling: AK47C2, Warlock ransomware, X2ANYLOCK / AK47 ransomware, Impacket - S0357, Mimikatz, PSEXEC, Project AK47, SharpHostInfo
How CVE-2026-45659 works
CVE-2026-45659 is a deserialization-of-untrusted-data remote code execution flaw in on-premises Microsoft SharePoint Server (Subscription Edition, 2019, and Enterprise Server 2016) that lets an authenticated Site Member trigger unsafe LosFormatter deserialization via the list-item Update() method. CISA added it to the KEV catalog on 2026-07-01 following confirmed active exploitation, with the activity associated with Storm-2603, a China-nexus actor that has exploited prior SharePoint flaws (the 2025 'ToolShell' chain) since mid-2025 to deploy Warlock/AK47 ransomware and the AK47C2 backdoor; the specific 2026-45659 exploitation method and campaign objectives remain unconfirmed as of this writing.
CVE-2026-45659 is a remote code execution vulnerability affecting on-premises Microsoft SharePoint Server (Subscription Edition, Server 2019, and Enterprise Server 2016 — SharePoint Online/Microsoft 365 are not affected). The root cause is unsafe deserialization of untrusted data: the vulnerable code path in Microsoft.SharePoint.Library invokes LosFormatter.Deserialize on attacker-controlled data passed through the Update() method of SPListItem objects when custom field types using ViewState-like serialization are processed, with no proper type filtering or ObjectStateFormatter restrictions in place. An authenticated attacker holding only Site Member-level permissions (PR:L) and Contribute rights to a list containing at least one editable item can submit a crafted serialized payload and achieve arbitrary code execution on the server over HTTPS, with no user interaction required and low attack complexity (CVSS 3.1: 8.8, AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Microsoft fixed the flaw in the May 2026 security updates (Subscription Edition build 16.0.19725.20280, Server 2019 build 16.0.10417.20128, Enterprise Server 2016 build 16.0.5552.1002), but the vulnerability was inadvertently omitted from the original security advisories and only formally disclosed alongside a parallel Microsoft Incident Response blog on 2026-06-22 describing related threat activity. CISA added CVE-2026-45659 to the Known Exploited Vulnerabilities (KEV) catalog on 2026-07-01 based on confirmed evidence of active exploitation in the wild, despite Microsoft's own severity tag of 'Exploitation Less Likely.' Federal Civilian Executive Branch (FCEB) agencies face a remediation deadline of 2026-07-04 under BOD 22-01/26-04. A public proof-of-concept exploit (Python, using the -t/-u/-p/-s/-c argument pattern against a target SharePoint list) is available on GitHub, demonstrating both single-command execution and interactive reverse-shell modes.
The activity is attributed to Storm-2603 (Palo Alto designation CL-CRI-1040), a China-nexus threat actor first identified during the July 2025 'ToolShell' SharePoint campaign (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771), which chained a spoofing bug and an RCE to drop the spinstall0.aspx web shell and exfiltrate SharePoint MachineKey material for forged ViewState/deserialization exploitation even after patching. That 2025 campaign affected at least 400 known victims globally and evolved into ransomware operations: Storm-2603 modified Group Policy Objects to mass-deploy Warlock ransomware, used BYOVD techniques and services.exe abuse to disable Defender, dumped LSASS credentials with Mimikatz, moved laterally with PsExec and Impacket, and used masscan/SharpHostInfo for internal reconnaissance. Storm-2603's custom 'Project AK47' toolkit includes the AK47C2 backdoor (DNS-based 'dnsclient' and HTTP-based 'httpclient' variants, both using a shared XOR key and JSON command protocol) and AK47/X2ANYLOCK ransomware (AES+RSA encryption, .x2anylock extension, Tox-based extortion negotiation). Infrastructure and Tox-ID overlap ties the 'wlteaml' LockBit 3.0 affiliate identity, the Warlock Client Leaked Data Show dark-web leak site, and prior LockBit Black double-extortion operations to the same actor cluster, indicating a hybrid espionage/financially-motivated operation blurring APT and ransomware-affiliate lines. As of the KEV addition, the specific exploitation vector and campaign goals for CVE-2026-45659 itself have not been publicly detailed, but the actor's established playbook (web shell/deserialization foothold → credential theft → lateral movement → GPO-based ransomware deployment) is the primary expected escalation path for unpatched, internet-facing SharePoint servers.
MITRE ATT&CK techniques used in TL-2026-1061
Credential Access
Discovery
T1016 System Network Configuration Discovery; T1120 Peripheral Device Discovery; T1135 Network Share Discovery
Lateral Movement
T1021 Remote Services; T1570 Lateral Tool Transfer
Defense Evasion
T1027 Obfuscated Files or Information
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1047 Windows Management Instrumentation; T1059 Command and Scripting Interpreter; T1059.001 PowerShell; T1059.003 Windows Command Shell; T1203 Exploitation for Client Execution
Persistence
T1053.005 Scheduled Task; T1505 Server Software Component; T1505.003 Web Shell; T1505.004 IIS Components
Command and Control
T1071.001 Web Protocols; T1071.004 DNS; T1090.002 External Proxy
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
defense-impairment
T1112 Modify Registry; T1685 Disable or Modify Tools
Collection
Privilege Escalation
T1484.001 Group Policy Modification
Impact
T1486 Data Encrypted for Impact
stealth
Affected products and versions in CVE-2026-45659
- Microsoft — SharePoint Server Subscription Edition
Vulnerable versions: pre-May 2026 update
Fixed in: 16.0.19725.20280 - Microsoft — SharePoint Server 2019
Vulnerable versions: pre-May 2026 update
Fixed in: 16.0.10417.20128 - Microsoft — SharePoint Enterprise Server 2016
Vulnerable versions: pre-May 2026 update
Fixed in: 16.0.5552.1002
Remediation for CVE-2026-45659
Patches
- Microsoft Security Update for SharePoint Server Subscription Edition (build 16.0.19725.20280, May 2026)
- Microsoft Security Update for SharePoint Server 2019 (build 16.0.10417.20128, May 2026)
- Microsoft Security Update for SharePoint Enterprise Server 2016 (build 16.0.5552.1002, May 2026)
Immediate actions
- Apply Microsoft's May 2026 SharePoint security updates: Subscription Edition build 16.0.19725.20280, Server 2019 build 16.0.10417.20128, Enterprise Server 2016 build 16.0.5552.1002
- Treat as a material update even if May 2026 patches were already applied without the advisory flag — verify build numbers directly
- Rotate SharePoint Server MachineKey (validationKey/decryptionKey) after patching to invalidate any ViewState/deserialization payloads forged with a stolen key
- Audit IIS logs and w3wp.exe process trees for anomalous child processes (cmd.exe, powershell.exe) following requests to SharePoint list/ToolPane endpoints
- Hunt for known Storm-2603 web shell artifacts (spinstall0.aspx and variants) and AK47C2 hashes/domains on internet-facing SharePoint servers
- Restrict Site Member self-service list creation/Contribute rights where not operationally required to reduce the exploitable attack surface
Workarounds
- If patching is delayed, restrict external network access to SharePoint Server admin/list endpoints via WAF or reverse proxy
- Disable or tightly scope custom field types with ViewState-like serialization where feasible until patched
Longer-term hardening
- Deploy EDR with behavioral detection on all SharePoint front-end and application servers, including LSASS access alerting
- Segment SharePoint servers from domain controllers and restrict GPO modification rights to break the observed GPO-based ransomware deployment path
- Implement AMSI integration and .NET deserialization allow-listing for custom SharePoint field types
- Establish a patch SLA for internet-facing SharePoint aligned with CISA KEV/BOD 26-04 timelines given repeated on-premises SharePoint exploitation since 2025
CVEs associated with CVE-2026-45659
CVE-2026-45659, CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771
Weaknesses (CWE) in CVE-2026-45659
Timeline of CVE-2026-45659
- Storm-2603/CL-CRI-1040 begins development of the Project AK47 toolkit (AK47C2 dnsclient v202503, later AK47/X2ANYLOCK ransomware).
- LockBit affiliate identity 'wlteaml' registers in the leaked LockBit database, later linked to Storm-2603 via shared Tox ID.
- The 'Warlock Client Leaked Data Show' double-extortion leak site emerges, later tied to the same Tox ID used by Storm-2603/AK47 ransomware.
- Storm-2603 begins exploiting the ToolShell SharePoint chain (CVE-2025-49704/49706/53770/53771), deploying the spinstall0.aspx web shell and stealing MachineKey material; ultimately affecting 400+ known victims.
- Microsoft publishes analysis of active on-premises SharePoint exploitation, attributing activity to Storm-2603, Linen Typhoon, and Violet Typhoon.
- Microsoft and researchers report Storm-2603 deploying Warlock and LockBit ransomware via GPO modification on compromised SharePoint-adjacent environments; DNS-controlled AK47C2 backdoor documented.
- A public Python proof-of-concept exploit for CVE-2026-45659 is published on GitHub, demonstrating remote command execution and interactive reverse-shell capability.
- Microsoft releases May 2026 security updates fixing CVE-2026-45659 across SharePoint Subscription Edition, 2019, and Enterprise Server 2016, though the CVE was initially omitted from public advisories.
- Microsoft Incident Response publishes a blog describing threat activity related to CVE-2026-45659, formally surfacing the advisory gap.
- CISA adds CVE-2026-45659 to the Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild and associating the activity with Storm-2603.
- The Hacker News publishes coverage of the KEV addition and Storm-2603 association, first observed by the harness via RSS.
- CISA-mandated remediation deadline for FCEB agencies to patch CVE-2026-45659 under BOD 22-01/26-04.
Sources cited for CVE-2026-45659
- SharePoint RCE (CVE-2026-45659) Added to CISA KEV Catalog
- Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions
- High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659)
- CVE-2026-45659-SharePoint-RCE proof-of-concept
- Known Exploited Vulnerabilities Catalog
- Storm-2603 Deploys DNS-Controlled Backdoor in Warlock and LockBit Ransomware Attacks
- Storm-2603 Exploits SharePoint Flaws to Deploy Warlock Ransomware on Unpatched Systems
- Project AK47: Uncovering a Link to the SharePoint Vulnerability Attacks
- Disrupting active exploitation of on-premises SharePoint vulnerabilities
- Before ToolShell: Exploring Storm-2603's Previous Ransomware Operations
- ToolShell under siege: Check Point analyzes Chinese APT Storm-2603
- Storm-2603: Targeting SharePoint Vulnerabilities and Critical Infrastructure Worldwide
- Microsoft SharePoint Has a New RCE Flaw. If You Haven't Patched Yet, Go Do That.
Detection coverage for TL-2026-1061
As of 2026-07-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1061 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.