The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about three critical vulnerabilities affecting Internet-exposed on-premises SharePoint Server instances. These security flaws, tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, are being actively exploited by attackers to gain unauthorized access, execute malicious code, and persist on compromised systems.
The vulnerabilities affect all supported self-hosted SharePoint Server versions, including the latest SharePoint Server Subscription Edition. This is particularly concerning because SharePoint servers are often used as a central hub for organizations to share files, collaborate, and manage workflow. When exposed to the internet, these servers become attractive targets for attackers seeking to exploit sensitive data.
As CISA notes in its advisory, the vulnerabilities can be exploited to bypass authentication, gain remote code execution, and carry out post-exploitation activity, including stealing Internet Information Services machine keys. This allows attackers to maintain persistence on compromised systems and deploy malware without detection. Additionally, two other SharePoint Server vulnerabilities (CVE-2026-55040 and CVE-2026-58644) have been patched by Microsoft but are considered attractive targets for attackers.
The CISA warning is backed up by data from Shadowserver, which tracks nearly 10,000 internet-exposed Microsoft SharePoint servers. Over 800 of these servers remain unpatched against the CVE-2026-32201 and CVE-2026-45659 vulnerabilities, making them vulnerable to attack. While there are no details on how many servers are affected by CVE-2026-56164 or if they are honeypots, the risk is clear.
To mitigate these risks, CISA recommends that security teams closely monitor affected servers for signs of exploitation and apply Microsoft’s latest patches as soon as possible. This includes verifying successful installation, shortening patching cycles, enabling Windows Antimalware Scan Interface (AMSI) integration for SharePoint web applications, and using Microsoft Defender Antivirus (MDAV) detections to detect and remediate compromise.
Additional hardening measures include hunting for and remediating intrusion artifacts before rotating IIS machine keys, establishing tailored logging to monitor for anomalous activity, avoiding direct internet exposure of SharePoint servers unless necessary, and reviewing Microsoft’s official SharePoint Server security-hardening guidance. It is also advisable to block external access to SharePoint Central Administration and restrict farm and database communication to the required systems.
In light of this warning, organizations should prioritize patching their SharePoint servers immediately. As CISA has noted in its advisory, federal agencies have until July 17 to secure SharePoint servers affected by CVE-2026-56164 under Binding Operational Directive (BOD) 26-04 or discontinue them if mitigations cannot be applied.
Ultimately, this warning serves as a reminder of the importance of regular patching and security monitoring. Organizations should test their defenses before attackers do, using breach and attack simulation tests to identify vulnerabilities in their systems. By taking proactive steps to secure their networks, organizations can reduce the risk of exploitation and minimize the impact of potential attacks.
Source: Bleeping Computer — 2026-07-15