Vulnerabilities · 3h ago
Warlock Keeps SharePoint as a Ransomware Doorway Symantec says Warlock, the China-nexus group also tracked as Longlegs and Storm-2603, kept abusing Microsoft SharePoint Server in the past two months, hitting at least four organizations in Portuguese- and Spanish-speaking countries. The victims included a water utility, a telecom provider, a regional government body, and a university.
The group’s playbook starts with SharePoint bugs, including the 2025 ToolShell flaws and newer CVEs, then moves into the Windows domain. Symantec says one intrusion used a tool to disable security software on at least 40 hosts, then staged Warlock in the domain’s SYSVOL share, which Windows replicates automatically, so the ransomware reached at least 33 systems without hand-copying it everywhere.
That makes the SharePoint server a launch point, not the end of the incident. If on-prem SharePoint sits inside the same domain as file shares and workstations, a single internet-facing foothold can turn into domain-wide ransomware spread and security-tool disablement.
CVEs in this update
10 CVEs
Across Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition.
4 critical · 2 high · 4 medium · 0 low
9 in CISA KEV · 5 with EPSS above 1%
4 with functional or packaged public exploit code
Highest severity: CVE-2025-53770 · 9.8 CRITICAL
Highest EPSS: CVE-2025-53770 · 100%
Timeline Oct 2 Reported by Industrial Cyber Oct 1 Reported by Dark Reading Aug 21 CISA federal deadline for CVE-2026-55040 passedAug 18 CVE-2026-55040 added to CISA KEVJul 25 CISA federal deadline for CVE-2026-50522 passedJul 22 CVE-2026-50522 added to CISA KEVJul 19 CISA federal deadline for CVE-2026-58644 passedJul 17 CISA federal deadline for CVE-2026-56164 passedJul 16 CVE-2026-58644 added to CISA KEVJul 14 CVE-2026-56164 added to CISA KEVJul 4 CISA federal deadline for CVE-2026-45659 passedJul 1 CVE-2026-45659 added to CISA KEVApr 28 CISA federal deadline for CVE-2026-32201 passedApr 14 CVE-2026-32201 added to CISA KEVJul 23 CISA federal deadline for CVE-2025-49704 passedJul 22 CVE-2025-49704 added to CISA KEVJul 21 CISA federal deadline for CVE-2025-53770 passedJul 20 CVE-2025-53770 added to CISA KEVSources 3 sources covering this story
Entities CVE-2025-49704 CVE-2025-49706 CVE-2025-53770 CVE-2025-53771 Warlock Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-10-02
Editions Related stories
Vulnerabilities · 3h ago
Warlock Keeps SharePoint as a Ransomware Doorway Symantec says Warlock, the China-nexus group also tracked as Longlegs and Storm-2603, kept abusing Microsoft SharePoint Server in the past two months, hitting at least four organizations in Portuguese- and Spanish-speaking countries. The victims included a water utility, a telecom provider, a regional government body, and a university.
The group’s playbook starts with SharePoint bugs, including the 2025 ToolShell flaws and newer CVEs, then moves into the Windows domain. Symantec says one intrusion used a tool to disable security software on at least 40 hosts, then staged Warlock in the domain’s SYSVOL share, which Windows replicates automatically, so the ransomware reached at least 33 systems without hand-copying it everywhere.
That makes the SharePoint server a launch point, not the end of the incident. If on-prem SharePoint sits inside the same domain as file shares and workstations, a single internet-facing foothold can turn into domain-wide ransomware spread and security-tool disablement.
CVEs in this update
10 CVEs
Across Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition.
4 critical · 2 high · 4 medium · 0 low
9 in CISA KEV · 5 with EPSS above 1%
4 with functional or packaged public exploit code
Highest severity: CVE-2025-53770 · 9.8 CRITICAL
Highest EPSS: CVE-2025-53770 · 100%
Timeline Oct 2 Reported by Industrial Cyber Oct 1 Reported by Dark Reading Aug 21 CISA federal deadline for CVE-2026-55040 passedAug 18 CVE-2026-55040 added to CISA KEVJul 25 CISA federal deadline for CVE-2026-50522 passedJul 22 CVE-2026-50522 added to CISA KEVJul 19 CISA federal deadline for CVE-2026-58644 passedJul 17 CISA federal deadline for CVE-2026-56164 passedJul 16 CVE-2026-58644 added to CISA KEVJul 14 CVE-2026-56164 added to CISA KEVJul 4 CISA federal deadline for CVE-2026-45659 passedJul 1 CVE-2026-45659 added to CISA KEVApr 28 CISA federal deadline for CVE-2026-32201 passedApr 14 CVE-2026-32201 added to CISA KEVJul 23 CISA federal deadline for CVE-2025-49704 passedJul 22 CVE-2025-49704 added to CISA KEVJul 21 CISA federal deadline for CVE-2025-53770 passedJul 20 CVE-2025-53770 added to CISA KEVSources 3 sources covering this story
Entities CVE-2025-49704 CVE-2025-49706 CVE-2025-53770 CVE-2025-53771 Warlock Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-10-02
Editions Related stories