CISA KEV Addition: Microsoft SharePoint Server Deserialization RCE (CVE-2026-45659) Actively Exploited by Storm-2603 / Warlock Ransomware — Threadlinqs Intelligence
As of 2026-07-05, CISA KEV Addition: Microsoft SharePoint Server Deserialization RCE (CVE-2026-45659) Actively Exploited by Storm-2603 / Warlock Ransomware is a critical-severity vulnerability threat attributed to Storm-2603 (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 34 indicators of compromise.
Threat ID: TL-2026-1123 · Severity: CRITICAL · CVSS: 8.8 · Status: ACTIVE · Category: VULNERABILITY
Attribution: Storm-2603 · China · FINANCIAL
CISA added CVE-2026-45659, a CWE-502 deserialization-of-untrusted-data RCE in on-premises Microsoft SharePoint Server, to its KEV catalog on 2026-07-01 citing active exploitation, with FCEB
CVE-2026-45659 is a remote code execution vulnerability (CVSS 3.1: 8.8) in Microsoft SharePoint Server caused by deserialization of untrusted data (CWE-502). The flaw affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. An authenticated attacker with only Site Member-level permissions (no elevated privileges, no user interaction) can submit a crafted serialized object to a SharePoint endpoint and trigger deserialization of attacker-controlled data, resulting in arbitrary code execution in the context of the SharePoint application pool (w3wp.exe).
Microsoft shipped the fix as an out-of-band security update on 2026-05-21 (build updates for all three product lines), but the CVE was inadvertently omitted from the official May 2026 Patch Tuesday release notes; Microsoft corrected the advisory on 2026-05-27. This omission meant organizations that reviewed the May release notes and saw no SharePoint entry may have deprioritized deployment of a patch they had, in fact, already received — a gap that active exploitation subsequently moved through. CVE-2026-45659 is part of a related deserialization vulnerability pair disclosed in the same update cycle alongside CVE-2026-47294 (CVSS 8.0, CWE-78 OS command injection via deserialization, requiring Site Owner privileges); no active exploitation of CVE-2026-47294 has been confirmed as of this writing.
CISA added CVE-2026-45659 to the Known Exploited Vulnerabilities (KEV) catalog on 2026-07-01, confirming in-the-wild exploitation and setting a BOD 26-04 remediation deadline of 2026-07-04 for FCEB agencies. Public exploit code purporting to target this CVE has since appeared on GitHub (mistbarbarianspot/CVE-2026-45659-SharePoint-RCE), increasing the population of capable attackers.
Post-exploitation activity observed in the wild mirrors the 2025 'ToolShell' SharePoint campaign (CVE-2025-49704/49706/53770/53771) run by Storm-2603 (aka Warlock Group / GOLD SALEM), a suspected China-based, financially motivated actor with a hybrid espionage/ransomware operating model. Attackers drop the spinstall0.aspx web shell to exfiltrate the SharePoint farm's ASP.NET machine keys (ValidationKey, DecryptionKey, CompatibilityMode), which are then used to forge valid ViewState payloads and re-authenticate as the server indefinitely, surviving simple patch application unless keys are rotated. From this foothold, actors have deployed the AK47C2 backdoor framework (dnsclient/httpclient modules communicating over DNS-TXT tunneling and HTTP POST with XOR-obfuscated JSON, key 'VHBD@H'), harvested credentials from LSASS via Mimikatz, moved laterally with PsExec/Impacket/WMI, disabled endpoint defenses via BYOVD (signed vulnerable driver abused with IOCTL 0x99000050) and DLL search-order hijacking (7z.exe/7z.dll, clink_x86.exe/clink_dll_x86.dll, spoofed Mpclient.dll beside MpCmdRun.exe), and ultimately deployed Warlock (aka X2anylock) and/or LockBit Black ransomware, in several cases pushed farm-wide via Group Policy modification. Microsoft investigators also identified a second, unrelated threat actor co-existing in at least one compromised environment, using distinct DLL side-loading tradecraft and custom backdoors, who subsequently pivoted into a second victim organization.
Victim sectors span government, healthcare, financial services, education, and critical infrastructure. Given the low bar for exploitation (any authenticated low-privilege user), the patch-notes omission that likely left many farms unpatched, and confirmed ransomware-capable actor involvement, this represents a critical, actively-exploited threat to any internet-facing or internally-exposed on-premises SharePoint deployment.
Target sectors: government administration, health, financial services, education, critical infrastructure
Target regions: North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-22, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 34 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-45659, T1190, T1569, T1047, T1505, T1053, T1574, T1562, T1036, T1484, T1027