CISA says Sharepoint bug CVE-2026-45659 is being exploited in the wild.
"If IIS is restarted without manually removing malicious module entries from applicationHost.config and web.config files, any malicious modules will persist and reload..."
"A modern zero-day chain with automatic shell drop, full persistence, and zero authentication"