“They exploited the ToolShell zero-day chain in July 2025 to deploy Warlock ransomware, and now they’re back doing the same thing with CVE-2026-45659,” said Calderone. “Warlock is built on the leaked LockBit 3.0 builder, but what separates them from typical LockBit affiliates is the zero-day access and the custom AK47 C2 framework they bring to engagements.”Roman Sannikov, global research coordinator at iCounter, said CVE-2026-45659 is a low complexity, minimal privileges required deserialization flaw on an on-premises SharePoint Server.Sannikov said initial access brokers look for that combination: something reliable enough to weaponize at scale and sell, rather than something one group has to painstakingly develop and keep to itself.“No specific ransomware gang has been named yet, and that tracks with how this usually plays out, access gets sold or handed off well before public attribution catches up,” said Sannikov. “Microsoft patched this in May, CISA confirmed active exploitation in July when it went on the KEV, and by August, that exploitation had turned into ransomware.”Sannikov pointed out that’s it’s been three months since the patch existed, and about a month of confirmed active exploitation on top of it, so it’s time for security teams to act.“SharePoint stores an organization’s internal documents, permissions, and often its most sensitive records,” said Sannikov. “An unpatched instance at this point usually comes down to a resourcing or prioritization gap inside the organization.”
