An old vulnerability family, still working
Symantec researchers are tracking continued exploitation of SharePoint by Warlock, a ransomware operation run by the China-based group Longlegs, which security researchers also track as Storm-2603 and link to related clusters CL-CRI-1040, CamoFei, and ChamelGang. The naming overlap itself reflects how fluid attribution has become in 2026, with the same infrastructure and tooling frequently reused across what look like distinct campaigns to outside observers. The attacks exploit what researchers describe as the ToolShell family of SharePoint flaws, a cluster of related vulnerabilities rather than a single CVE, spanning at least six identifiers disclosed months ago: CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522, and CVE-2026-55040.
The headline here is the staying power of old vulnerabilities rather than the discovery of a new one. Every one of these CVEs has a patch available, several of them for months. Symantec's research exists at all because organizations in the exploitation data set have not applied those patches, well after public disclosure gave every defender equal notice that this vulnerability family was a live and actively discussed threat across the security community.
Who keeps getting hit
Recent Warlock targets concentrate in water utilities, telecommunications providers, government agencies, and educational institutions, with a geographic skew toward Portuguese and Spanish-speaking regions, suggesting either a deliberate regional focus or simply a cluster of unpatched, internet-reachable SharePoint instances the group happened to find first in those markets. That sector mix is a familiar one in 2026's threat reporting: critical infrastructure operators and public-sector organizations running SharePoint on-premises, often without the dedicated patch-management staffing that commercial enterprises in better-resourced sectors take for granted as a baseline cost of doing business.
Water utilities specifically have shown up repeatedly across 2026's critical infrastructure attack reporting, a pattern that reflects structural underinvestment rather than bad luck. These organizations typically run lean IT staffs managing both operational technology and office productivity systems like SharePoint with the same small team, which means a patch backlog on the IT side competes directly for attention against operational uptime concerns on the OT side, and operational uptime usually wins that fight until it is too late.
Why six CVEs matter more than one
A single critical vulnerability is relatively straightforward to communicate up the chain: patch this one thing by this date, confirm it, close the ticket. A cluster of six related CVEs spanning multiple disclosure dates over several months is a different and much harder operational problem, because it requires an organization to track a moving vulnerability family rather than close a single ticket once and move on. A team that patched against the first disclosure in the cluster may reasonably believe it already handled SharePoint for the quarter and redirect attention to the next fire, never circling back when the fourth or fifth related CVE in the same family shows up weeks later under a different identifier.
That is almost certainly part of why Warlock's campaign remains productive months after the first disclosure in the cluster. Attackers benefit directly from exactly this kind of fragmented disclosure pattern, because it creates a long tail of organizations that patched partially, patched against the wrong CVE in the cluster while believing they had closed the whole issue, or patched on time for the first disclosure and then deprioritized SharePoint entirely once that initial ticket closed, never revisiting it when the next related CVE landed. Each of those partial-patch states looks identical from the outside to a fully unpatched system, which is exactly what Warlock's operators are counting on when they scan broadly rather than target a specific known-vulnerable organization.
The attribution detail enterprise risk teams should actually use
The China-nexus attribution to Longlegs and its related clusters functions best as an operational signal about target selection and patience, rather than as a geopolitical data point on its own. Groups in this cluster, including ChamelGang, have a documented history of opportunistic, infrastructure-focused targeting that favors whatever unpatched system is reachable over highly bespoke campaigns built around a single named target. That targeting logic explains why a six-CVE SharePoint cluster disclosed months ago keeps producing fresh victims: the group is sweeping broadly for whichever SharePoint instance in its preferred sector mix never got patched, confident that the sweep alone will keep finding new entry points without any need to study a specific organization in advance.
For enterprise risk teams, the practical takeaway is to treat vulnerability clusters, not individual CVEs, as the unit of remediation tracking. If your organization runs SharePoint on-premises and has any exposure to the sectors Warlock favors, directly or through a vendor or partner relationship, confirming patch status against the full six-CVE list, not just the first one your team remembers handling, is a same-week action item rather than a next-quarter one.
The uncomfortable pattern across 2026's zero-day news
Warlock's continued success against SharePoint sits alongside a steady drumbeat of 2026 disclosures involving edge infrastructure and collaboration platforms, a category that keeps producing fresh exploitation months after patches exist. Symantec's own framing centers the problem squarely on organizational patch discipline failing to keep pace with disclosure volume: old, known, patchable vulnerabilities keep remaining viable for attackers simply because defenders have not closed them out, a gap that reflects process maturity far more than it reflects any new leap in attacker sophistication. The pattern repeats closely enough across 2026's incident reporting that it has become a predictable shape: a patch ships, most organizations apply it within a reasonable window, and a meaningful minority do not, and that minority supplies the victim pool for every follow-on campaign for months afterward.
That diagnosis should change how security leaders prioritize their limited attention. A sophisticated zero-day with no available patch is a genuine emergency that justifies compensating controls and vendor escalation, and it deserves to be treated as one. A known, patched vulnerability still being exploited months later is a process failure instead, and the fix for it is unglamorous but concrete: inventory every SharePoint instance in the environment, confirm patch status against the complete CVE cluster rather than just the first entry in it, and treat any remaining gap as a finding that goes to the CISO directly, by name, rather than sitting quietly in a ticket queue waiting for a quieter week that never comes.



