CVE-2026-45659: Microsoft SharePoint RCE Weaponized by Storm-2603 Warlock Ransomware — CISA KEV, Federal Deadline July 4
How Storm-2603 weaponized a SharePoint deserialization flaw to deploy Warlock ransomware across enterprise networks.
This post is part of the Week of July 3, 2026 Security Roundup.
Vulnerability Overview
CVE-2026-45659 (CVSS 8.8, CWE-502) is a deserialization of untrusted data vulnerability in Microsoft SharePoint Server. Patched in Microsoft's May 2026 Patch Tuesday, active exploitation was confirmed this week. CISA added it to the Known Exploited Vulnerabilities catalog on July 2, 2026, with a federal FCEB remediation deadline of July 4, 2026. Exploitation has been attributed to Storm-2603, deploying Warlock ransomware.
Affected Versions
- SharePoint Server Subscription Edition — pre-June 2026 CU → Apply June 2026 CU
- SharePoint Server 2019 → Apply KB5002694
- SharePoint Enterprise Server 2016 → Apply KB5002695
Technical Analysis
SharePoint uses .NET's BinaryFormatter in internal API handlers for cross-server communication and legacy workflow compatibility. CVE-2026-45659 targets a handler that processes HTTP POST bodies without validating the caller's privileges or sanitizing the deserialized type chain.
Exploitation requirements:
- Valid SharePoint account with minimum Site Member permissions — a standard user account, easily obtained via phishing or credential spray
- Network access to the SharePoint server on TCP 443
- No admin privileges required
Exploitation steps:
- Attacker authenticates with a low-privilege SharePoint account.
- A crafted HTTP POST containing a malicious
BinaryFormatter-serialized .NET object chain (e.g., via ysoserial.net gadget chains) is sent to the vulnerable API handler. - SharePoint deserializes the payload, executing attacker-supplied .NET code in the context of
w3wp.exe(the SharePoint application pool process). - Code runs as the application pool identity — typically
DOMAIN\SP_WebApporNetworkService— a domain account with elevated intranet access. - Storm-2603 deploys a Cobalt Strike beacon or Warlock dropper via PowerShell, then proceeds to credential harvesting, lateral movement, and ransomware deployment.
Storm-2603 Threat Profile
Storm-2603 is a financially motivated threat cluster tracked by Microsoft since mid-2025 with a focus on on-premises enterprise infrastructure. The group targets internet-facing SharePoint, Exchange, and Citrix deployments opportunistically and maintains a low operational tempo to avoid detection before deploying ransomware.
Warlock Ransomware Technical Details
- Encryption: ChaCha20 per-file with per-file keys; RSA-4096 key wrapping
- C2: HTTPS with certificate pinning; Tor-proxied fallback (
warlock[.]onion) - Ransom note:
WARLOCK_RESTORE.txtin every encrypted directory - Encrypted extension:
.warlock - Pre-encryption activities: credential dumping (Mimikatz), AD reconnaissance (BloodHound CE), data exfiltration (double extortion)
- Shadow copy deletion:
vssadmin delete shadows /all /quiet - Staging path:
C:\ProgramData\Microsoft\Windows\Templates\ - Persistence: Scheduled task named
MicrosoftEdgeUpdateorWindowsSecurityHealth
Detection and Threat Hunting
# Hunt for Warlock ransom notes
Get-ChildItem C:\ -Recurse -Filter "WARLOCK_RESTORE.txt" -ErrorAction SilentlyContinue
# SharePoint ULS logs — deserialization errors
Get-Content "C:\Program Files\Common Files\microsoft shared\Web Server Extensions\LOGS\*.log" |
Select-String "BinaryFormatter|TypeLoadException|deserializ" | Select-Object -Last 50
# Unexpected w3wp.exe child processes (Sysmon Event ID 1)
Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-Sysmon/Operational'; Id=1} |
Where-Object {$_.Message -match 'ParentImage.*w3wp' -and $_.Message -match 'powershell|cmd|wscript'}
# Outbound Tor connections from SharePoint servers
# Look for CONNECT requests to .onion proxy (127.0.0.1:9050) or unusual outbound TCP 9001/9030
Remediation
# Verify current SharePoint patch level
(Get-SPFarm).BuildVersion
# Apply patches:
# SharePoint 2019: https://support.microsoft.com/kb/5002694
# SharePoint 2016: https://support.microsoft.com/kb/5002695
# Immediate mitigation if patching is delayed:
# Require VPN for all SharePoint access; remove from public internet
# Audit SharePoint permissions — remove any unused accounts with Site Member+
Get-SPSite -Limit All | Get-SPWeb -Limit All |
ForEach-Object {$_.SiteUsers | Where-Object {$_.IsSiteAdmin -eq $false}}