CISA Warns: SharePoint Flaw Now Used in Ransomware Attacks

What happened
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware operators are now actively exploiting a high-severity remote code execution vulnerability in Microsoft SharePoint. The flaw has been flagged as under active exploitation since early July, and CISA's latest update escalates the risk profile from opportunistic probing to full ransomware deployment. The reporting comes from BleepingComputer.
The affected systems are on-premises SharePoint servers, which remain common in small and mid-sized businesses that either kept a legacy intranet, host document libraries locally for compliance reasons, or run SharePoint alongside Microsoft 365 in a hybrid configuration. If you are unsure whether your environment includes an on-prem SharePoint instance, that is itself the first thing worth verifying this week — check with your IT team before assuming the exposure does not apply to you.

Why this matters for Pittsburgh SMBs
Ransomware crews prey on exactly the kind of businesses we serve across Western PA: 10 to 200 employees, valuable data, and lean internal IT. SharePoint is a particularly attractive target because it typically sits at the center of a company's document workflow — contracts for a Downtown law firm, patient intake for a South Hills practice, engineering drawings for a manufacturer in the Mon Valley, or CUI-adjacent project files for a defense contractor supporting Pittsburgh's growing robotics and additive-manufacturing base. Encrypt or exfiltrate SharePoint and you have effectively taken the business hostage.
The compliance angle makes this worse, not better. If you fall under HIPAA, SOC 2, the FTC Safeguards Rule, or you are on the road to CMMC Level 2, an unpatched, actively exploited CVE on an internet-reachable server is the kind of finding that turns a security incident into a regulatory event. For DFARS 7012 reporters, a ransomware event that touches CUI carries a 72-hour DoD reporting clock. For healthcare clients, HHS breach notification timelines apply the moment you cannot rule out unauthorized access. Speed of patching is now a compliance question, not just an IT hygiene question.
One more local note: several regional ransomware incidents over the past year have entered through exactly this pattern — a public-facing Microsoft server, a known CVE, a patch window that stretched past the point when exploit code went public. Do not assume "we are too small to be scanned." Automated scanners do not care about your revenue.
What to do about it this week
Here is a concrete checklist you can run through between now and next Monday. If you are a PGH Networks managed IT client, most of this is already in motion; use it as a verification list.
- Inventory your SharePoint footprint. Confirm whether you run SharePoint Server on-prem (2016, 2019, or Subscription Edition), a hybrid configuration, or SharePoint Online only. SharePoint Online (part of Microsoft 365) is patched by Microsoft; on-prem is your responsibility. If nobody on your team can answer this in an hour, that is the finding.
- Apply Microsoft's SharePoint security updates immediately. Verify the specific KB numbers and CVE identifiers against Microsoft's Security Update Guide for your exact SharePoint build — do not rely on a generic "we patch monthly" answer. If your maintenance window is weeks away, this one warrants an emergency change.
- Check for indicators of compromise before you patch. Patching a box that is already compromised only closes the front door. Review IIS logs, w3wp.exe child processes, unexpected .aspx files in LAYOUTS directories, and any new local admin accounts. Your EDR or MDR provider should be pulling this proactively.
- Restrict SharePoint exposure to the internet. If your on-prem SharePoint does not need to be reachable from the public internet, put it behind the VPN or a ZTNA broker. If it does, front it with a WAF and geo-restrict where it makes sense.
- Test your backups — actually restore something. Ransomware playbooks target backup infrastructure first. Verify you have immutable or offline copies of SharePoint content databases and that a restore has been rehearsed within the last 90 days. As of today, August 11, 2026, that means a successful test on or after May 13.
- Rotate machine account and service credentials associated with the SharePoint farm, especially if the server was internet-facing at any point since early July. Assume credentials that touched that box could be replayed.
- Brief your users. Ransomware follow-on activity often includes phishing that impersonates SharePoint sharing notifications. A one-paragraph note from leadership goes a long way this week.

How PGH Networks helps
This is the day-to-day work of our managed IT and cybersecurity teams: emergency patch management for critical CVEs, 24/7 EDR/MDR monitoring for the exploitation patterns CISA is describing, and hardening for Microsoft 365 and hybrid SharePoint environments. For regulated clients, our vCIO team ties the technical response to your HIPAA, SOC 2, or CMMC obligations so a patch cycle also becomes documented evidence. If you are not sure whether your environment is exposed, that uncertainty is the problem we solve first.
Talk to us
Call 724.888.7007 or reach out through the contact form and we will help you confirm your SharePoint exposure, verify patch status, and review what your monitoring would have caught if this had hit you last week.
Related reading

Active SharePoint Exploit: What Pittsburgh SMBs Should Do Now
Attackers are exploiting a critical Microsoft SharePoint flaw in the wild. Here is what Pittsburgh SMBs should verify, patch, and monitor this week.

Microsoft 365 AitM Phishing Is Hunting Your Payroll Inbox
An active Microsoft 365 AitM phishing campaign is hijacking finance and payroll mailboxes at SMBs. Here is what Pittsburgh businesses should do this week.

Kali365 Device-Code Phishing: What M365 Tenants Should Do Now
Kali365 hijacks Microsoft 365 accounts via device-code phishing. What Pittsburgh SMBs should check in Entra ID this week, plus a 7-step action list.