The federal government keeps a running list of the software flaws attackers are actually using — not theoretical ones, the ones with live victims. It is a JSON file, 1,662 entries long this week, and most weeks it just grows quietly at the bottom. This week an existing entry changed instead. CVE-2026-45659 — a deserialization flaw that lets an attacker with any foothold account execute code on an on-prem SharePoint server, CVSS 8.8 — has sat in the catalog since July 1. Its ransomware field said “Unknown.” It now says “Known.”
Look at the spacing of the dates, because the spacing is the story. Microsoft published the vulnerability, fix available, on May 22. CISA added it to the catalog on July 1 and gave federal agencies until July 4 to remediate — three days, over a holiday weekend, the kind of fuse the agency reserves for active harm. Through July, three more SharePoint flaws joined the list behind it. And as of the catalog stamped August 10, the first one carries the ransomware flag. Every week a client’s server sat unpatched inside that span has just been converted from a backlog item into a question.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 Prioritizing Security Updates Based on Risk … guidance and CISA's "Forensics Triage Requirements" … or discontinue use of the product if mitigations are unavailable.
Read that required action a second time. It does not say “patch.” It says patch and follow the forensics-triage guidance — CISA telling its own agencies that for this entry, remediation includes looking backward. That is the honest standard for your clients too. The orgs still running SharePoint on-prem in 2026 are exactly the ones that couldn’t leave it: the regulated, the legacy-bound, the underfunded. If one of their servers took the May update in July or August — or hasn’t yet — installing the patch today closes the door without checking whether anyone came through it. The flaw was being exploited before it made the catalog. The window was real.
There is also a deliverable in this, and it is not a scary email. It is one paragraph per client, with dates in it: here is every SharePoint server you own, here is the day each one took the May update, and here is what we did about the ones that waited. The day a client’s insurer, auditor, or attacker forces the question, that paragraph is the difference between an answer and a scramble — and you can be the one who wrote it first.
Three moves. Inventory — every on-prem SharePoint box across your clients, including the “temporary” ones and the one behind the VPN nobody logs into. Prove the patch date — not “we’re current,” but the install date per server, written down while the logs still have it. Triage the laggards — any server that sat unpatched past July 1 gets treated as a question to answer per the catalog’s linked forensics guidance, not a task to close.
Kept honest. “Known” means CISA has evidence this flaw has been used in ransomware campaigns somewhere — it is not a claim that any particular org was hit, and the catalog does not name the gangs or the victims. The 8.8 score reflects a real precondition: the attacker needs an authenticated foothold first, which is what phishing is for. The three July SharePoint entries still carry “Unknown” on their ransomware fields today. And the July 4 deadline legally bound federal civilian agencies, not your clients — but it remains the plainest signal of urgency the government publishes, and it was three days.
Sources, all primary, all fetched today, August 11, 2026. (1) CISA, Known Exploited Vulnerabilities Catalog, JSON feed, catalog version 2026.08.10, 1,662 entries, fetched and read today — cisa.gov/known-exploited-vulnerabilities-catalog. Source of the CVE-2026-45659 entry: dateAdded 2026-07-01, federal dueDate 2026-07-04, knownRansomwareCampaignUse “Known,” the required-action text quoted verbatim above including BOD 26-04 and the Forensics Triage Requirements references; and of the three July SharePoint entries CVE-2026-56164 (added July 14), CVE-2026-58644 (July 16), and CVE-2026-50522 (July 22), all currently “Unknown” on ransomware use. (2) NIST, National Vulnerability Database record for CVE-2026-45659, fetched today — nvd.nist.gov/vuln/detail/CVE-2026-45659. Source of the May 22, 2026 publication date, the CVSS 3.1 base score 8.8 HIGH, and the deserialization-of-untrusted-data description (CWE-502). The flag flip was reported by trade press today; every fact above was taken from the catalog and the NVD record directly, not from coverage.
One field flipped in a government JSON file this week, and it's worth two minutes of your attention if any client of yours still runs SharePoint on-prem. CISA's Known Exploited Vulnerabilities catalog — the list of flaws with confirmed live victims — has carried CVE-2026-45659 since July 1. It's a deserialization hole in SharePoint Server: an attacker with any foothold account gets code execution on the box. As of this week's catalog, its ransomware-use field reads "Known." Here's the timeline that matters more than the CVE number. Fix published May 22. Added to the catalog July 1 — with a federal remediation deadline of July 4. Three days, over a holiday weekend. That's the fuse CISA reserves for active harm. Three MORE SharePoint flaws joined the list through July. Now the first one is confirmed in ransomware campaigns. Every week a server sat unpatched inside that span just converted from a backlog item into a question. And notice what the catalog's required action actually says: apply the fix AND follow CISA's forensics-triage guidance. Not just patch — look backward. This flaw was being exploited before it made the list. A server that took the May update in late July closed the door without checking whether anyone came through it. The deliverable I'd build this week is one paragraph per client, with dates: every SharePoint server, the day each took the May update, and what we did about the ones that waited. When an insurer or auditor forces the question, that paragraph is the difference between an answer and a scramble. Honest caveats: "Known" means used in ransomware campaigns somewhere, not that your client was hit. And the attacker needs an authenticated foothold first — which is what phishing is for. The fix shipped in May. The flag flipped in August. The space between is what you're accountable for now.
A finished, narrated animation of this edition came with your email (MP4, 1080×1350 — sized for LinkedIn and Instagram). Post it as-is.
FIRST SOURCE · one verified original-source finding, composed for one reader · this edition: cybersecurity — written for the people whose clients will ask if this one was handled, and expect dates in the answer