Filed under: Cybersecurity · Ransomware · July 2026

What happened

A flaw in Microsoft SharePoint Server (CVE-2026-45659) is being actively exploited, and CISA added it to its Known Exploited Vulnerabilities list on July 1 with a July 4 patch deadline for federal agencies — about as urgent as those deadlines get. The bug lets attackers run their own code on the server remotely, and at least one group exploiting it, Storm-2603, follows up by deploying Warlock ransomware. Important: this affects on-premises SharePoint Server only — SharePoint Online, the version included with Microsoft 365, is not affected.

Why it matters to your business

Plenty of small businesses had a SharePoint server installed years ago for file sharing and haven’t touched it since — which is exactly the profile this gang targets. An old server sitting in a closet, reachable from the internet, missing patches: that’s not a file server anymore, it’s a ransomware entry point. If you’re fully on Microsoft 365, you can relax on this one. If you’re not sure which you have, that uncertainty is itself the finding.

What to do this week

Ask one question: “Do we run SharePoint on our own server?” If yes, apply Microsoft’s latest SharePoint Server security update now — not at the next maintenance window — and check whether the server actually needs to be reachable from the internet at all. If the server is old enough that it no longer gets updates, it’s time to plan a migration to SharePoint Online, where Microsoft does the patching for you.

The bigger picture

Ransomware gangs don’t break in through your newest system — they scan for the oldest thing you forgot you owned. Once files are encrypted, options shrink fast; the only reliable recovery is never letting them in. Why the Only True Recovery from Ransomware Is Prevention

Do you know every server your business still runs — and who’s patching them? Book a free consult → https://micro1tech.com/contact/