(TLP:CLEAR) Ransomware Groups Now Targeting Recently Disclosed SharePoint and SonicWall Vulnerabilities
Created: Thursday, August 13, 2026 - 15:21
Categories: Cybersecurity, Federal & State Resources, Security Preparedness
Summary: CISA has confirmed ransomware operators are now exploiting vulnerabilities in Microsoft SharePoint and SonicWall SMA1000 appliances, adding updates to its Known Exploited Vulnerabilities catalog. WaterISAC sent vulnerability notifications to members in July for these vulnerabilities.
For SharePoint, CISA confirmed ransomware activity tied to CVE-2026-45659, a high-severity remote code execution flaw stemming from deserialization of untrusted data. It allows an attacker with low privileges to run arbitrary code on unpatched servers, and Microsoft has noted it can be exploited reliably in low-complexity attacks. The flaw affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. WaterISAC notified members of this vulnerability on July 14, in its Vulnerability Notification – Microsoft SharePoint Server Actively Exploited.
Separately, CISA linked ransomware activity to two SonicWall SMA1000 flaws (CVE-2026-15409 and CVE-2026-15410), including a maximum-severity server-side request forgery vulnerability. SMA1000 is a secure remote access gateway used to provide VPN access to internal networks. Resecurity, a cyber threat intelligence firm, has associated the attacks with an affiliate of the INC Ransomware operation. WaterISAC notified members of these vulnerabilities on July 16 in its Vulnerability Notification – SonicWall SMA1000 Zero-Days Actively Exploited.
Analyst Note: Both products are common in enterprise and utility environments, and internet-facing SharePoint servers and remote access gateways are attractive footholds for initial access. The shift from zero-day and general exploitation to confirmed ransomware use raises the urgency, since financially motivated operators tend to move quickly once working exploits circulate. Utilities running these products can confirm patches are applied, verify successful installation, and review internet exposure. Members who identify related activity are encouraged to report findings to WaterISAC.
Original Sources:
- https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-flaw-now-exploited-in-ransomware-attacks/
- https://www.bleepingcomputer.com/news/security/sonicwall-sma1000-flaws-exploited-as-zero-days-to-push-custom-malware/
Related WaterISAC PIRs: 6, 7, 7.1, 8, 10, 12
