AL
Analyst accessPublic view · sign in

Vulnerability threat dossier

CVE-2026-45659

Vendor unknownProduct mapping pending

Metadata pending authoritative retrieval.

VTP deterministic threat49.3of 100 · CVSS excluded

VTP analyst assessment

Second KEV SharePoint mapping linked to ransomware

AI-assisted analytical recommendationDoes not set factual exploitation state
AI classificationURGENT
AI priorityCRITICAL
AI confidence72%
Public exploitation · VTP factKEV

Assessment

CVE-2026-45659 is also KEV-listed and mapped by the same secondary report to ransomware exploitation and a public PoC. Analysts should urgently determine whether both CVEs are implicated or whether the report-to-CVE resolution is overly broad.

Why it matters

  • CISA KEV establishes known global exploitation.
  • New reporting associates the flaw with ransomware activity.
  • The same report also asserts a public PoC, although reliability is unverified.
  • The evidence is one chain shared with CVE-2026-33825 rather than an independent confirmation.
  • No first-party sensor telemetry is configured.

Evidence

1 evidence references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

No first-party sensor telemetry is configured. Local exploitation observation is unknown.

Next watchpoint · deterministic

A validated functional exploit or automated exploitation capability would materially change this assessment.

Review statePROPOSED
AI analysis history (2)
  1. URGENT
    Second KEV SharePoint mapping linked to ransomwaregpt-5.6-sol · high
  2. URGENT
    Ransomware exploitation reported for KEV-listed SharePoint vulnerabilitygpt-5.6-sol · high

Previous AI priority: CRITICAL → current: CRITICAL. Inspect the evidence preserved for each run before treating this as a threat transition.

Technical severityUNKNOWNCVSS unknown · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityPOCReliability not implied
EPSS0.0995th percentile · prediction
Evidence confidence60%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryNo first-party sensor telemetry configured.
Availability: NO_SENSOR_CONFIGURED · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    A proof of concept is reported; functional reliability is not established.

  3. 03

    EPSS is 0.09; this is predictive context, not exploitation evidence.

  4. 04

    No first-party sensor telemetry is configured; first-party observation is unknown.

02

Material change ledger

What changed

KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

1publications detected
1underlying evidence chains

0 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:42d27d84cb8dc4d5380210e8badf255430cd22203d84680aefe9c5dc76635cbdACTIVE
Evidence
Source claimPOC AVAILABLEPUBLICATION REPORTS POC
60%claim confidence
UNKNOWNreport:42d27d84cb8dc4d5380210e8badf255430cd22203d84680aefe9c5dc76635cbdACTIVE
Evidence
04

Event history

Threat timeline

  1. 12:1211 Aug
    EXPLOITATION REPORTED

    Exploitation Reported

    BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.

  2. 12:1211 Aug
    POC AVAILABLE

    Poc Available

    BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.

  3. 00:0001 Jul
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. [...]

CVE-2026-33825CVE-2026-45659
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score49.3vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction1.82 / 20
Exploit availability7.5 / 15
Source independence0 / 15
Intelligence recency10 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
Unknown · UNKNOWN
Vector
Unknown
CWE
Unknown
CPE records
0
Deterministic history records
3
07

Raw observations

First-party sensor records

No first-party sensor telemetry configured.