Critical SharePoint Vulnerabilities Being Actively Exploited, CISA Warns
A major cybersecurity threat has been identified by the US Cybersecurity and Infrastructure Security Agency (CISA), which warns that attackers are actively exploiting three vulnerabilities in Microsoft’s popular SharePoint Server software. The affected flaws, tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, allow hackers to bypass authentication, gain remote code execution, and carry out post-exploitation activity on compromised systems.
The problem is widespread, with over 800 Internet-exposed SharePoint servers found to be unpatched against the CVE-2026-32201 and CVE-2026-45659 vulnerabilities. This has raised concerns that these systems may already have been hacked, as hackers can use these flaws to steal sensitive data or deploy malware on compromised systems.
The vulnerabilities in question affect all supported self-hosted SharePoint Server versions, including the latest Subscription Edition (which uses a “continuous update” model). These flaws are being actively exploited by attackers, who are using them to gain unauthorized access to sensitive data and disrupt business operations. CISA has added these vulnerabilities to its Known Exploited Vulnerabilities Catalog, which means that federal agencies have until July 17 to secure their SharePoint servers or discontinue them if mitigations cannot be applied.
To protect against this threat, CISA recommends that security teams take immediate action by applying Microsoft’s latest patches and verifying successful installation. Shortening patching cycles is also crucial, as it allows administrators to respond quickly to emerging threats. Additionally, enabling Windows Antimalware Scan Interface (AMSI) integration for SharePoint web applications and using Microsoft Defender Antivirus (MDAV) detections can help detect and remediate compromise.
Furthermore, CISA advises that additional hardening measures be taken, such as hunting for and remediating intrusion artifacts before rotating IIS machine keys, establishing tailored logging to monitor for anomalous activity, and reviewing Microsoft’s official SharePoint Server security-hardening guidance. Blocking external access to SharePoint Central Administration and restricting farm and database communication to required systems can also help prevent attacks.
In the wake of this warning, it is essential that organizations take proactive measures to protect their systems from these vulnerabilities. By staying informed about emerging threats and taking prompt action to address them, organizations can minimize the risk of a successful attack.
Ultimately, the takeaway from this warning is clear: security teams must be vigilant and proactive in monitoring their systems for signs of exploitation. This means staying up-to-date with the latest patches, enabling robust logging and detection capabilities, and regularly reviewing system configuration to ensure that it remains secure. By doing so, organizations can protect themselves against these types of threats and prevent devastating attacks from occurring in the first place.
Source: Bleeping Computer — 2026-07-15