CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities

US Cybersecurity Agency Sounds Alarm on Exploited SharePoint Vulnerabilities

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal agencies and organizations worldwide, urging them to immediately patch vulnerable Microsoft SharePoint servers. The agency’s alert comes in response to a trio of zero-day vulnerabilities that have been exploited by attackers, with potentially devastating consequences.

At the center of the crisis is CVE-2026-56164, a privilege escalation flaw that allows remote access without authentication. This vulnerability was addressed through Microsoft’s July 2026 Patch Tuesday updates, but its inclusion in CISA’s Known Exploited Vulnerabilities (KEV) catalog underscores its severity and the need for swift action. The agency recommends that organizations prioritize patching this vulnerability within three days, as outlined in BOD 26-04 recommendations.

However, the scope of the issue extends beyond CVE-2026-56164. CISA also draws attention to two critical-severity SharePoint bugs, CVE-2026-55040 and CVE-2026-58644, which could be exploited remotely to bypass security features and execute arbitrary code. While these vulnerabilities have not been explicitly flagged as exploited, their potential impact should not be underestimated.

Another vulnerability that has caught CISA’s attention is CVE-2026-45659, a code execution issue patched in May through an out-of-band update. This flaw was added to the KEV list in early July and poses significant risks if left unpatched. The agency warns that these vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016), enabling attackers to establish remote code execution (RCE) and engage in post-exploitation activities such as stealing Internet Information Services (IIS) machine keys and performing deserialization techniques.

To mitigate the risks associated with these vulnerabilities, CISA recommends that organizations take several steps. First, they should monitor their SharePoint servers for signs of unusual activity, which could indicate active exploitation. Additionally, organizations are advised to apply Microsoft’s patches, ensure that security products cover all SharePoint web applications, hunt for intrusions, rotate IIS machine keys, enable tailored logging, and restrict access to administration interfaces.

In the face of these threats, it is essential for organizations to take proactive measures to protect themselves. This includes staying up-to-date with the latest security updates, conducting regular vulnerability assessments, and implementing robust security controls to prevent exploitation. By taking these steps, organizations can significantly reduce their exposure to these types of attacks and safeguard their sensitive data.

In light of this alert, it is essential for all SharePoint administrators and IT teams to take immediate action to patch vulnerable systems and ensure that their security measures are up-to-date. By doing so, they can protect themselves from potential attacks and prevent the devastating consequences that exploitation of these vulnerabilities could bring.


Source: SecurityWeek — 2026-07-15