• News/
  • bleepingcomputer-20260715094452

CISA warns admins to patch actively exploited SharePoint flaws

BleepingComputer
·
Sergiu Gatlan
·
Published Jul 15, 2026
·
Updated

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. These security flaws (tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) affect all supported self-hosted SharePoint Server versions, including SharePoint Server Subscription Edition (the latest on-premises version, which uses a "continuous update" model). As detailed in a Tuesday advisory, attackers are exploiting these vulnerabilities to bypass authentication, gain remote code execution, and carry out post-exploitation activity, including stealing Internet Information Services machine keys and gaining persistence to deploy malware on compromised systems. The U.S. cybersecurity agency also flagged two more SharePoint Server vulnerabilities (CVE-2026-55040 and CVE-2026-58644), which Microsoft patched on Tuesday and tagged as attractive targets for attackers, although they are not yet known to have been exploited in the wild. Internet security watchdog group Shadowserver currently tracks nearly 10,000 Internet-exposed Microsoft SharePoint servers, with over 800 of them unpatched against the CVE-2026-32201 and CVE-2026-45659 vulnerabilities. However, there are no details on how many of them are vulnerable to CVE-2026-56164 attacks or are honeypots. CISA urged security teams to closely monitor affected servers for signs of exploitation and recommended applying Mi...

Read full article

Affected Software

1 affected component
Microsoft SharePoint Server>=all supported self-hosted versions
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerabilities are being actively exploited according to CISA?

CISA has identified three vulnerabilities tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 that are being actively exploited.

2

Which software is affected by these vulnerabilities?

The vulnerabilities specifically affect on-premises Microsoft SharePoint Server instances.

3

What does CISA recommend to protect against these vulnerabilities?

CISA recommends that administrators patch their systems to mitigate the risks associated with these actively exploited vulnerabilities.

4

Why is it crucial for administrators to act on these warnings?

It's crucial for administrators to act because these vulnerabilities are being actively exploited by attackers, potentially leading to security breaches.

5

When was the warning about these vulnerabilities published by CISA?

The warning was published by CISA on July 15, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203