The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. These security flaws (tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) affect all supported self-hosted SharePoint Server versions, including SharePoint Server Subscription Edition (the latest on-premises version, which uses a "continuous update" model). As detailed in a Tuesday advisory, attackers are exploiting these vulnerabilities to bypass authentication, gain remote code execution, and carry out post-exploitation activity, including stealing Internet Information Services machine keys and gaining persistence to deploy malware on compromised systems. The U.S. cybersecurity agency also flagged two more SharePoint Server vulnerabilities (CVE-2026-55040 and CVE-2026-58644), which Microsoft patched on Tuesday and tagged as attractive targets for attackers, although they are not yet known to have been exploited in the wild. Internet security watchdog group Shadowserver currently tracks nearly 10,000 Internet-exposed Microsoft SharePoint servers, with over 800 of them unpatched against the CVE-2026-32201 and CVE-2026-45659 vulnerabilities. However, there are no details on how many of them are vulnerable to CVE-2026-56164 attacks or are honeypots. CISA urged security teams to closely monitor affected servers for signs of exploitation and recommended applying Mi...
CISA warns admins to patch actively exploited SharePoint flaws
BleepingComputer
·Sergiu Gatlan
·Published Jul 15, 2026
·Updated
Affected Software
1 affected component
Microsoft SharePoint Server>=all supported self-hosted versions
Frequently Asked Questions
1
What vulnerabilities are being actively exploited according to CISA?
CISA has identified three vulnerabilities tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 that are being actively exploited.
2
Which software is affected by these vulnerabilities?
The vulnerabilities specifically affect on-premises Microsoft SharePoint Server instances.
3
What does CISA recommend to protect against these vulnerabilities?
CISA recommends that administrators patch their systems to mitigate the risks associated with these actively exploited vulnerabilities.
4
Why is it crucial for administrators to act on these warnings?
It's crucial for administrators to act because these vulnerabilities are being actively exploited by attackers, potentially leading to security breaches.
5
When was the warning about these vulnerabilities published by CISA?
The warning was published by CISA on July 15, 2026.