Threat reportVulnerabilityTL-2026-1061

CVE-2026-45659: SharePoint Deserialization RCE Added to CISA KEV Amid Storm-2603 Exploitation

highACTIVE

CVE-2026-45659 (TL-2026-1061), also tracked as ToolShell (related 2025 campaign), is a high-severity software vulnerability scored CVSS 8.8, first published 2026-07-02. It is attributed to Storm-2603 (China) with medium confidence, affects Microsoft SharePoint Server Subscription Edition, references 5 CVEs (CVE-2026-45659, CVE-2025-49704, CVE-2025-49706), maps to 28 MITRE ATT&CK techniques (T1003.001, T1016, T1021), and is covered by 9 detection rules and 30 indicators of compromise.

CVSS
8.8/10High
CVEs
5Referenced vulnerabilities
Techniques
28MITRE ATT&CK
Actors
1Storm-2603
Detection rules
9SPL · KQL · Sigma
IOCs
30Indicators of compromise

Key facts for TL-2026-1061

Threat ID
TL-2026-1061
Also known as
ToolShell (related 2025 campaign), Project AK47
Severity
HIGH
CVSS
8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution
Storm-2603
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
FINANCIAL
Target sectors
government administration, criticalinfrastructure, professionalservices, finance, manufacturing, education
Target regions
North America, Asia-Pacific, Latin America, Europe
Detection rules
9
Indicators of compromise
30

Malware and tooling in CVE-2026-45659

Malware and tooling: AK47C2, Warlock ransomware, X2ANYLOCK / AK47 ransomware, Impacket - S0357, Mimikatz, PSEXEC, Project AK47, SharpHostInfo

How CVE-2026-45659 works

CVE-2026-45659 is a deserialization-of-untrusted-data remote code execution flaw in on-premises Microsoft SharePoint Server (Subscription Edition, 2019, and Enterprise Server 2016) that lets an authenticated Site Member trigger unsafe LosFormatter deserialization via the list-item Update() method. CISA added it to the KEV catalog on 2026-07-01 following confirmed active exploitation, with the activity associated with Storm-2603, a China-nexus actor that has exploited prior SharePoint flaws (the 2025 'ToolShell' chain) since mid-2025 to deploy Warlock/AK47 ransomware and the AK47C2 backdoor; the specific 2026-45659 exploitation method and campaign objectives remain unconfirmed as of this writing.

CVE-2026-45659 is a remote code execution vulnerability affecting on-premises Microsoft SharePoint Server (Subscription Edition, Server 2019, and Enterprise Server 2016 — SharePoint Online/Microsoft 365 are not affected). The root cause is unsafe deserialization of untrusted data: the vulnerable code path in Microsoft.SharePoint.Library invokes LosFormatter.Deserialize on attacker-controlled data passed through the Update() method of SPListItem objects when custom field types using ViewState-like serialization are processed, with no proper type filtering or ObjectStateFormatter restrictions in place. An authenticated attacker holding only Site Member-level permissions (PR:L) and Contribute rights to a list containing at least one editable item can submit a crafted serialized payload and achieve arbitrary code execution on the server over HTTPS, with no user interaction required and low attack complexity (CVSS 3.1: 8.8, AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Microsoft fixed the flaw in the May 2026 security updates (Subscription Edition build 16.0.19725.20280, Server 2019 build 16.0.10417.20128, Enterprise Server 2016 build 16.0.5552.1002), but the vulnerability was inadvertently omitted from the original security advisories and only formally disclosed alongside a parallel Microsoft Incident Response blog on 2026-06-22 describing related threat activity. CISA added CVE-2026-45659 to the Known Exploited Vulnerabilities (KEV) catalog on 2026-07-01 based on confirmed evidence of active exploitation in the wild, despite Microsoft's own severity tag of 'Exploitation Less Likely.' Federal Civilian Executive Branch (FCEB) agencies face a remediation deadline of 2026-07-04 under BOD 22-01/26-04. A public proof-of-concept exploit (Python, using the -t/-u/-p/-s/-c argument pattern against a target SharePoint list) is available on GitHub, demonstrating both single-command execution and interactive reverse-shell modes.

The activity is attributed to Storm-2603 (Palo Alto designation CL-CRI-1040), a China-nexus threat actor first identified during the July 2025 'ToolShell' SharePoint campaign (CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771), which chained a spoofing bug and an RCE to drop the spinstall0.aspx web shell and exfiltrate SharePoint MachineKey material for forged ViewState/deserialization exploitation even after patching. That 2025 campaign affected at least 400 known victims globally and evolved into ransomware operations: Storm-2603 modified Group Policy Objects to mass-deploy Warlock ransomware, used BYOVD techniques and services.exe abuse to disable Defender, dumped LSASS credentials with Mimikatz, moved laterally with PsExec and Impacket, and used masscan/SharpHostInfo for internal reconnaissance. Storm-2603's custom 'Project AK47' toolkit includes the AK47C2 backdoor (DNS-based 'dnsclient' and HTTP-based 'httpclient' variants, both using a shared XOR key and JSON command protocol) and AK47/X2ANYLOCK ransomware (AES+RSA encryption, .x2anylock extension, Tox-based extortion negotiation). Infrastructure and Tox-ID overlap ties the 'wlteaml' LockBit 3.0 affiliate identity, the Warlock Client Leaked Data Show dark-web leak site, and prior LockBit Black double-extortion operations to the same actor cluster, indicating a hybrid espionage/financially-motivated operation blurring APT and ransomware-affiliate lines. As of the KEV addition, the specific exploitation vector and campaign goals for CVE-2026-45659 itself have not been publicly detailed, but the actor's established playbook (web shell/deserialization foothold → credential theft → lateral movement → GPO-based ransomware deployment) is the primary expected escalation path for unpatched, internet-facing SharePoint servers.

MITRE ATT&CK techniques used in TL-2026-1061

Credential Access

T1003.001 LSASS Memory

Discovery

T1016 System Network Configuration Discovery; T1120 Peripheral Device Discovery; T1135 Network Share Discovery

Lateral Movement

T1021 Remote Services; T1570 Lateral Tool Transfer

Defense Evasion

T1027 Obfuscated Files or Information

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1047 Windows Management Instrumentation; T1059 Command and Scripting Interpreter; T1059.001 PowerShell; T1059.003 Windows Command Shell; T1203 Exploitation for Client Execution

Persistence

T1053.005 Scheduled Task; T1505 Server Software Component; T1505.003 Web Shell; T1505.004 IIS Components

Command and Control

T1071.001 Web Protocols; T1071.004 DNS; T1090.002 External Proxy

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

defense-impairment

T1112 Modify Registry; T1685 Disable or Modify Tools

Collection

T1119 Automated Collection

Privilege Escalation

T1484.001 Group Policy Modification

Impact

T1486 Data Encrypted for Impact

stealth

T1574.001 DLL

Affected products and versions in CVE-2026-45659

  • Microsoft — SharePoint Server Subscription Edition
    Vulnerable versions: pre-May 2026 update
    Fixed in: 16.0.19725.20280
  • Microsoft — SharePoint Server 2019
    Vulnerable versions: pre-May 2026 update
    Fixed in: 16.0.10417.20128
  • Microsoft — SharePoint Enterprise Server 2016
    Vulnerable versions: pre-May 2026 update
    Fixed in: 16.0.5552.1002

Remediation for CVE-2026-45659

Patches

  • Microsoft Security Update for SharePoint Server Subscription Edition (build 16.0.19725.20280, May 2026)
  • Microsoft Security Update for SharePoint Server 2019 (build 16.0.10417.20128, May 2026)
  • Microsoft Security Update for SharePoint Enterprise Server 2016 (build 16.0.5552.1002, May 2026)

Immediate actions

  • Apply Microsoft's May 2026 SharePoint security updates: Subscription Edition build 16.0.19725.20280, Server 2019 build 16.0.10417.20128, Enterprise Server 2016 build 16.0.5552.1002
  • Treat as a material update even if May 2026 patches were already applied without the advisory flag — verify build numbers directly
  • Rotate SharePoint Server MachineKey (validationKey/decryptionKey) after patching to invalidate any ViewState/deserialization payloads forged with a stolen key
  • Audit IIS logs and w3wp.exe process trees for anomalous child processes (cmd.exe, powershell.exe) following requests to SharePoint list/ToolPane endpoints
  • Hunt for known Storm-2603 web shell artifacts (spinstall0.aspx and variants) and AK47C2 hashes/domains on internet-facing SharePoint servers
  • Restrict Site Member self-service list creation/Contribute rights where not operationally required to reduce the exploitable attack surface

Workarounds

  • If patching is delayed, restrict external network access to SharePoint Server admin/list endpoints via WAF or reverse proxy
  • Disable or tightly scope custom field types with ViewState-like serialization where feasible until patched

Longer-term hardening

  • Deploy EDR with behavioral detection on all SharePoint front-end and application servers, including LSASS access alerting
  • Segment SharePoint servers from domain controllers and restrict GPO modification rights to break the observed GPO-based ransomware deployment path
  • Implement AMSI integration and .NET deserialization allow-listing for custom SharePoint field types
  • Establish a patch SLA for internet-facing SharePoint aligned with CISA KEV/BOD 26-04 timelines given repeated on-premises SharePoint exploitation since 2025

CVEs associated with CVE-2026-45659

CVE-2026-45659, CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771

Weaknesses (CWE) in CVE-2026-45659

CWE-502

Timeline of CVE-2026-45659

  • Storm-2603/CL-CRI-1040 begins development of the Project AK47 toolkit (AK47C2 dnsclient v202503, later AK47/X2ANYLOCK ransomware).
  • LockBit affiliate identity 'wlteaml' registers in the leaked LockBit database, later linked to Storm-2603 via shared Tox ID.
  • The 'Warlock Client Leaked Data Show' double-extortion leak site emerges, later tied to the same Tox ID used by Storm-2603/AK47 ransomware.
  • Storm-2603 begins exploiting the ToolShell SharePoint chain (CVE-2025-49704/49706/53770/53771), deploying the spinstall0.aspx web shell and stealing MachineKey material; ultimately affecting 400+ known victims.
  • Microsoft publishes analysis of active on-premises SharePoint exploitation, attributing activity to Storm-2603, Linen Typhoon, and Violet Typhoon.
  • Microsoft and researchers report Storm-2603 deploying Warlock and LockBit ransomware via GPO modification on compromised SharePoint-adjacent environments; DNS-controlled AK47C2 backdoor documented.
  • A public Python proof-of-concept exploit for CVE-2026-45659 is published on GitHub, demonstrating remote command execution and interactive reverse-shell capability.
  • Microsoft releases May 2026 security updates fixing CVE-2026-45659 across SharePoint Subscription Edition, 2019, and Enterprise Server 2016, though the CVE was initially omitted from public advisories.
  • Microsoft Incident Response publishes a blog describing threat activity related to CVE-2026-45659, formally surfacing the advisory gap.
  • CISA adds CVE-2026-45659 to the Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild and associating the activity with Storm-2603.
  • The Hacker News publishes coverage of the KEV addition and Storm-2603 association, first observed by the harness via RSS.
  • CISA-mandated remediation deadline for FCEB agencies to patch CVE-2026-45659 under BOD 22-01/26-04.

Sources cited for CVE-2026-45659

Detection coverage for TL-2026-1061

As of 2026-07-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1061 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
30 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats