# Ransomware Gangs Have Moved Into SharePoint — And CISA Is Telling You to Run
Six weeks. That's roughly how long it took ransomware operators to move from "someone interesting found this" to "we're deploying payloads through SharePoint." CISA's confirmation this week that a high-severity Microsoft SharePoint remote code execution vulnerability is now being weaponized in ransomware campaigns should not read as a surprise. It should read as a timer going off.
The flaw was flagged as actively exploited in early July. Now it's a ransomware vector. The distance between those two facts is the entire modern threat lifecycle, compressed.
## What's Actually At Stake Here
SharePoint isn't a niche product. It's the backbone of document management, internal portals, and collaboration workflows at enterprises worldwide — Fortune 500 companies, government agencies, healthcare systems, law firms. The organizations that live in SharePoint tend to be the ones with sensitive documents worth encrypting and ransoming.
Remote code execution on a SharePoint server doesn't just hand an attacker one machine. It drops them into the center of a network where their victims have already done the work of aggregating valuable files. It's the difference between robbing a single drawer and robbing the room where everyone keeps their drawers.
The attack surface is compounded by how SharePoint is deployed. Many organizations expose their on-premises SharePoint instances to the internet for remote access — a necessity that became a liability the moment this vulnerability entered active exploitation. Cloud-only SharePoint Online configurations through Microsoft 365 have different risk profiles, but hybrid deployments are common, and the blast radius for those is significant.
## The July-to-Ransomware Pipeline
The exploitation timeline here follows a pattern that defenders should have committed to memory by now.
A vulnerability gets discovered and patched. A handful of technically sophisticated actors begin probing it — initially state-linked groups, sometimes pure criminal operators with access to quality research. CISA adds it to the Known Exploited Vulnerabilities catalog, which triggers a patching deadline for federal agencies (typically 21 days for high-severity flaws). Then, within weeks, the commodity ransomware ecosystem catches up.
This isn't a slow leak. There's now an active secondary market for weaponized exploits, and once a vulnerability is confirmed exploitable in the wild, tooling proliferates fast. Initial access brokers — specialists who compromise environments and sell footholds to ransomware affiliates — are particularly aggressive about operationalizing high-value enterprise flaws.
SharePoint hits every criterion these brokers value: it's widely deployed, often internet-facing, usually holds a privileged network position, and the organizations running it have the revenue profiles that justify ransom demands worth paying.
## What CISA's Confirmation Actually Means
There's a difference between "exploited by nation-state actors in targeted intrusions" and "exploited by ransomware gangs." The latter is operationally noisier, less targeted, and more likely to hit your organization. Ransomware operators typically aren't after specific targets — they're scanning, finding, and encrypting at scale. If your SharePoint is exposed and unpatched, you're a target by definition.
CISA's addition of a vulnerability to the KEV catalog used to be primarily relevant to federal civilian agencies, which face mandatory patching deadlines under Binding Operational Directive 22-01. But security teams outside the federal space have learned to treat KEV additions as an urgent signal — they represent confirmed, active exploitation, not theoretical risk.
The ransomware confirmation elevates the urgency further. This is no longer a vulnerability being used in careful, targeted campaigns where the average enterprise sits safely outside the blast radius. Ransomware actors operate broadly.
## Patching Is Not Optional, But It's Also Not Sufficient
Organizations that applied Microsoft's patch when it released are in reasonable shape. Organizations that haven't — and there are always organizations that haven't — need to move today, not at the next scheduled maintenance window.
But patching alone closes the door without checking whether someone is already inside. The exploitation timeline means some environments may have been compromised during the window between vulnerability disclosure and patch application, or through delayed patching cycles.
Security teams should be looking at:
If you don't have the visibility to do that retrospective analysis, the gap in your detection capability is a separate, compounding problem.
## The Hybrid Deployment Blind Spot
One detail that deserves more attention: organizations running hybrid SharePoint environments — on-premises servers federated with SharePoint Online — face risk that purely cloud-based tenants don't. The RCE vulnerability targets the server component. Microsoft's patch addresses the on-premises side; cloud tenants don't carry the same exposure.
But hybrid deployments are common precisely because organizations use on-premises SharePoint for sensitive or regulated data they're not ready to move to the cloud. The sites with the most to lose from a ransomware attack are often the ones with on-premises infrastructure that was patched last, if at all.
---
## HackWire Analysis
The pattern emerging here is one the enterprise security community should name clearly: Microsoft's collaboration and productivity stack has become the preferred ransomware on-ramp.
Look at the last five years. Exchange Server vulnerabilities (ProxyLogon, ProxyShell, ProxyNotShell) were serially weaponized for ransomware and espionage. Teams and Outlook have been targeted for phishing and credential theft. SharePoint has now joined that list in an unambiguous way.
This isn't a coincidence. Microsoft's enterprise products are ubiquitous, often internet-facing by design, and deeply integrated into organizational networks in ways that give attackers immediate access to valuable targets once they're in. Defenders have known this implicitly, but the industry discourse still treats each individual Microsoft CVE as an isolated event rather than a structural pattern that warrants a different defensive posture.
What that posture looks like: tighter network segmentation around SharePoint and Exchange infrastructure, more aggressive patching SLAs for Microsoft enterprise products specifically (assume exploitation within weeks, not months), and incident response playbooks that specifically address the "SharePoint compromised, what's the blast radius" scenario before it's relevant.
The other thing other coverage is missing: this is a ransomware confirmation, but the initial exploitation in early July was almost certainly not ransomware actors. Sophisticated initial exploiters — often state-linked — operated in this window before the commodity ecosystem caught up. Organizations in sensitive sectors (defense contractors, legal, healthcare, critical infrastructure) should assume the possibility of a quiet intrusion predating any ransomware-related activity and treat forensic review accordingly.
CISA flagged it. Ransomware actors confirmed it. The only remaining question is whether your patch Tuesday backlog did.
— HackWire Editorial
---
## Related Coverage