What's new: BleepingComputer, published after the prior summary, dates one intrusion’s security-tool takedown to 22 July 2026 on at least 40 hosts using K7RKScan CVE-2025-1055 and Warlock encryption of at least 33 hosts to 31 July, and it repeats the 2025 ToolShell CVEs rather than SecurityWeek’s 2026 IDs.
Merged summary · grok-4.7 · rewritten as coverage arrives
A China-linked group deployed Warlock ransomware via SharePoint flaws against water, telecom, government, and university targets; sources disagree on countries and CVE IDs.
Reporting on 1–2 October 2026 says a China-linked actor is deploying Warlock ransomware against at least four organizations over about two months, including a water utility, a telecommunications provider, a regional government body, and a university. Cyber Security News, SecurityWeek, The Record, and BleepingComputer, citing Symantec, name the operator Longlegs (Microsoft: Storm-2603), and Cyber Security News also links it to ChamelGang/CamoFei, while Dark Reading describes only a year-old Chinese actor that mixes cybercrime with state-associated APT behavior and gives no victims or technical detail. Geography is disputed: Dark Reading says large organizations in Spain and Portugal, whereas the Symantec-based reports say Portuguese- and Spanish-speaking countries, with Cyber Security News and The Record placing them across Europe, Africa, and Latin America. Vulnerability IDs also conflict: Cyber Security News and BleepingComputer cite SharePoint ToolShell flaws CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771 plus driver CVE-2025-1055; SecurityWeek lists 2026 flaws including CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164; The Record says both the 2025 ToolShell bugs and newer 2026 flaws highlighted by CISA were used. In one intrusion, endpoint protection was disabled on about 40 systems and Warlock encrypted at least 33, with BleepingComputer dating those events to 22 July and 31 July 2026 and the ransomware staged on the domain SYSVOL share; reports also describe webshells, machine-key theft, NetExec, and Visual Studio Code tunnels. The Record adds that the operators previously used LockBit, that Microsoft could not link them to another tracked Chinese state group, and that a related SharePoint campaign last year was alleged to have affected at least 400 organizations, including the National Nuclear Security Administration, NIH, and DHS.
Symantec-cited outlets identify the operator as China-nexus Longlegs (Microsoft: Storm-2603); Cyber Security News also links it to ChamelGang/CamoFei. They say Warlock hit at least four organizations in about two months: a water utility, a…
Dark Reading instead describes a year-old Chinese actor that blends cybercrime with state-associated APT behavior, names no victims or flaws, and says large organizations in Spain and Portugal were hit.
Cyber Security News and The Record place victims in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America; SecurityWeek says Portuguese- and Spanish-speaking countries.
China-nexus Longlegs deploys Warlock ransomware via exploited SharePoint flaws against water utility, telecom, government, and university targets across three continents.
A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege user to send crafted IOCTL requests to…
Authenticated Code Injection RCE in Microsoft SharePoint
CVE IDs conflict: Cyber Security News and BleepingComputer cite SharePoint ToolShell CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771 plus K7RKScan driver CVE-2025-1055; SecurityWeek cites 2026 flaws including…
In one intrusion, security tools were disabled on about 40 hosts—BleepingComputer dates that to 22 July 2026, and Cyber Security News says the killer reached roughly 40 hosts in two hours—and Warlock encrypted at least 33 systems on 31…
Reported activity also includes webshells, ASP.NET machine-key theft, NetExec, DLL sideloading, and Visual Studio Code tunnels.
The Record says the operators previously used LockBit, Microsoft could not tie them to another tracked Chinese state group, and a related SharePoint campaign last year was alleged to have hit at least 400 organizations, including the…
A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege user to send crafted IOCTL requests to…
A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege user to send crafted IOCTL requests to terminate a wide range of processes running with administrative or system-level privileges, with the exception of those inherently protected by the operating system. This flaw stems from missing access control in the driver's IOCTL handler, enabling unprivileged users to perform privileged actions in kernel space. Successful exploitation can lead to denial of service by disrupting critical services or privileged applications.
Authenticated Code Injection RCE in Microsoft SharePoint
CVE-2025-49704 is a code injection vulnerability (CWE-94) in Microsoft SharePoint that allows an authorized (authenticated) attacker to execute arbitrary code on the server over the network, by sending requests whose attacker-controlled input SharePoint executes as code. It can be chained with CVE-2025-49706, and Microsoft subsequently issued CVE-2025-53770 as a patch bypass of the original CVE-2025-49704 fix, meaning the CVE-2025-53770 updates provide stronger protection and should be treated as the definitive remediation. Successful exploitation yields remote code execution on the SharePoint server, and CISA added the flaw to the KEV on 2025-07-22 with known ransomware use. Organizations running on-premises SharePoint Server are affected; CISA directs owners of public-facing servers running EOL/EOS versions (SharePoint Server 2013 and earlier) to disconnect them, and operators of supported versions to apply the CISA and vendor mitigations and updates, with cloud SharePoint services governed by BOD 22-01. Exploitation is confirmed in the wild and EPSS assigns a 100% probability of exploitation within 30 days (top percentile), although no public proof-of-concept code is documented.
Do: Apply Microsoft's SharePoint Server updates for CVE-2025-53770, which supersede the original CVE-2025-49704 fixes with more robust protection, prioritizing internet-facing servers. Disconnect public-facing SharePoint servers running EOL/EOS versions (SharePoint Server 2013 and earlier), and for supported versions follow the CISA and vendor mitigations, with cloud services handled per BOD 22-01. Because in-the-wild exploitation and ransomware use are confirmed, hunt for indicators of compromise and ransomware activity on exposed SharePoint servers.
8.8
group max
100%
KEV ransomware
Microsoft SharePoint CISA lists 'Microsoft SharePoint' without enumerating specific version ranges; the CISA KEV guidance targets on-premises SharePoint Server, calling out SharePoi
masstens of thousands of internet-exposed SharePoint servers per public scans, within a total on-premises install base plausibly exceeding 100,000 deployments…
Unauthenticated Deserialization RCE in Microsoft SharePoint Server on-premises
CVE-2025-53770 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft SharePoint Server on-premises that allows an unauthorized attacker to execute code over a network. It is triggered when the server deserializes attacker-controlled data, can be chained with CVE-2025-53771, and it bypasses the fixes issued for CVE-2025-49704, meaning the earlier patches are insufficient. Successful exploitation yields remote code execution on the SharePoint server, and ransomware operators are known to be using it. Any organization running SharePoint Server on-premises is affected, particularly internet-facing deployments and end-of-life versions such as SharePoint Server 2013 and earlier that can no longer be patched. The flaw is being actively exploited — it was added to CISA's KEV on 2025-07-20 with known ransomware use — and EPSS assigns it a 100% probability of exploitation within 30 days.
Do: Apply Microsoft's updated SharePoint Server security updates that fix CVE-2025-53770 — these include more robust protection than the earlier CVE-2025-49704 updates — and ensure the companion CVE-2025-53771 is also addressed, following CISA and vendor mitigation instructions for supported versions. Disconnect public-facing SharePoint Server 2013 or earlier (EOL/EOS) instances, minimize internet exposure of supported servers, and hunt for signs of compromise given the known ransomware exploitation.
Improper Authentication in Microsoft SharePoint Server Enables Network Spoofing
CVE-2025-53771 is an improper authentication flaw (CWE-287) in Microsoft's on-premises SharePoint Server that allows an unauthenticated remote attacker to conduct spoofing over the network. Per the CVSS vector, exploitation requires no privileges and no user interaction, so an attacker who can reach the SharePoint server over the network can trigger it directly. Successful exploitation lets the attacker impersonate an authenticated user or component, producing limited but real impact on confidentiality and integrity (CVSS 6.5, medium). Any organization running on-premises SharePoint Server is affected, particularly those exposing it to the internet; no specific version numbers are provided in the source data, so defenders should consult Microsoft's advisory for their edition. No public PoC exists and it is not yet in CISA's KEV, but exploitation likelihood is near-certain (EPSS 99.7%, 100th percentile), and Microsoft has confirmed active China-linked nation-state exploitation of the closely related SharePoint ToolShell vulnerability chain, which has hit roughly 400 organizations including U.S. federal agencies.
Do: Apply Microsoft's SharePoint Server security updates that ship this fix as soon as possible, prioritizing internet-facing servers, and treat this as urgent because it was patched alongside the actively exploited ToolShell chain. While patching, review authentication and web-server logs on SharePoint hosts for unexpected successful logons or anomalous requests that could indicate spoofing or compromise, and restrict network access to SharePoint (VPN, firewall rules, segmentation) if patching must be delayed.
Improper Input Validation Spoofing Vulnerability in Microsoft SharePoint Server
Microsoft SharePoint Server contains an improper input validation flaw (CWE-20) that can be triggered by an unauthenticated, network-based attacker submitting crafted input to the server. Successful exploitation allows the attacker to perform spoofing over the network, impersonating a trusted user or source within SharePoint; detailed impact mechanics have not been published and no CVSS score or public proof-of-concept is available. Any organization running on-premises Microsoft SharePoint Server is potentially affected, and the available data does not specify affected version ranges. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2026-04-14, indicating evidence of active exploitation, and EPSS assigns a 42.8% probability of exploitation within 30 days (99th percentile). Ransomware association is currently unknown.
Do: Apply Microsoft's security updates for SharePoint Server per the vendor advisory as soon as possible, and identify your SharePoint Server versions and builds since specific affected ranges are not provided here. Given the KEV listing, federal agencies must apply the vendor mitigations, follow applicable BOD 22-01 cloud guidance, or discontinue use by the established deadline. Until patched, limit network exposure of SharePoint servers and review authentication and access logs for signs of impersonation or spoofing activity.
Authenticated Deserialization RCE in Microsoft SharePoint Server (Actively Exploited)
CVE-2026-45659 is a deserialization-of-untrusted-data vulnerability (CWE-502) in Microsoft SharePoint Server in which an authorized (authenticated, low-privilege) attacker can submit crafted serialized data over the network, with no user interaction required, to execute code on the server. Successful exploitation carries high impact on confidentiality, integrity, and availability within the SharePoint service context, giving attackers a foothold for follow-on activity, and CISA notes that ransomware use is known. Organizations running on-premises Microsoft SharePoint Server are affected; the source data lists no specific version ranges, and the CPE scope (sharepoint server) points to the on-premises product rather than the Microsoft-managed SharePoint Online service. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-01 after active exploitation, and its EPSS score of 76.1% (100th percentile) indicates a high probability of near-term exploitation. The CVE record lists no public proof-of-concept, though related reporting describes exploitation activity following a public PoC release for a SharePoint authentication bypass.
Do: Apply Microsoft's current security updates for SharePoint Server following vendor instructions, prioritizing internet-facing servers, and comply with CISA BOD 26-04, which requires applying mitigations per vendor guidance (including the cited Forensics Triage Requirements) or discontinuing use of the product if mitigations are unavailable. Because in-the-wild exploitation and ransomware use are confirmed, triage exposed servers for compromise: review IIS/SharePoint logs for unexpected authenticated requests, look for webshells or newly modified files in SharePoint web roots, and check for unusual child processes spawned by the SharePoint application pool. Given related reporting on an authentication-bypass PoC, also verify that any related SharePoint authentication-bypass patches are…
Unauthenticated Deserialization RCE in Microsoft SharePoint Server
CVE-2026-58644 is a critical (CVSS 9.8) deserialization-of-untrusted-data flaw (CWE-502) in Microsoft SharePoint Server that allows an unauthorized attacker to execute code over a network. An attacker triggers it by sending crafted serialized data to the server, with no privileges or user interaction required, gaining code execution in the context of the SharePoint service. Any organization running on-premises SharePoint Server is affected, with highest risk for instances reachable from the internet or by untrusted network users. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-07-16, and contemporaneous headlines describe an exploited SharePoint zero-day, indicating active in-the-wild exploitation; EPSS assigns a roughly 16% probability of exploitation within 30 days (97th percentile). Fixes shipped in Microsoft's July 2026 Patch Tuesday release (621 CVEs total), while no public proof-of-concept for this specific CVE is documented.
Do: Apply Microsoft's July 2026 Patch Tuesday security updates for SharePoint Server immediately, prioritizing internet-facing instances, as required for federal agencies under CISA BOD 26-04 and the KEV listing. If patching must be delayed, restrict network exposure to SharePoint per Microsoft/CISA mitigation guidance and assess each asset's internet exposure. Review SharePoint and web-server logs for signs of exploitation and enumerate all SharePoint Server installations in the environment to confirm coverage.
Missing Authentication in Microsoft SharePoint Server Allows Privilege Escalation
Microsoft SharePoint Server contains a missing authentication for critical function vulnerability (CWE-306) that lets an unauthenticated attacker elevate privileges over a network without valid credentials. The flaw is triggered when the affected SharePoint function is accessed remotely without any authentication check, allowing an attacker to gain higher privileges than intended. Successful exploitation could enable an attacker to take elevated actions within the SharePoint environment, potentially leading to further compromise of the server and its data. All organizations running on-premises Microsoft SharePoint Server are potentially affected, though specific versions have not yet been enumerated by Microsoft or CISA. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-14, indicating it is being actively exploited, and its EPSS score of 26.6% (98th percentile) reflects a high near-term exploitation risk.
Do: Apply Microsoft's security updates for SharePoint Server as soon as they are available, and check Microsoft's advisory for the specific affected version ranges once published. In the meantime, restrict network access to SharePoint servers, especially for internet-facing instances, and verify whether your environment falls under CISA BOD 26-04 requirements given the KEV listing. Monitor for updated guidance from Microsoft and CISA, as exploitation is confirmed and patching urgency is high.
9.8
1%
KEV
Microsoft SharePoint Server
Microsoft SharePoint Server (on-premises) Specific version ranges not enumerated in the source data; Microsoft SharePoint on-premises is affected. CISA notes SharePoint Server 2013 and earlier are EOL/E
mass≈25,000–100,000 internet-exposed on-premises SharePoint servers (public internet-wide scans); total on-prem installed base plausibly >1M users
KEV
large
Tens of thousands of internet-facing SharePoint Server deployments, with a total on-prem installed base plausibly in the hundreds of thousands (estimate)
mass
likely on the order of 100,000+ on-premises SharePoint Server installations, of which tens of thousands are directly internet-exposed
KEV
KEV
ransomware
Microsoft SharePoint Server
mass≈100,000 internet-exposed SharePoint Server deployments (order-of-magnitude estimate), with total users across on-premises deployments likely in the millions
KEV
KEV
Microsoft SharePoint Server (on-premises)
masson the order of 100,000+ on-prem SharePoint Server deployments, with tens of thousands likely internet-exposed (estimate)
KEV
mass
potentially millions of users and well over 100,000 exposed installations worldwide