The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a group of exploited vulnerabilities in Microsoft SharePoint servers. These flaws, which include remote code execution and privilege escalation issues, can be exploited by attackers without needing any authentication. CISA is urging all federal agencies to patch these vulnerabilities within the next three days.
The most recent vulnerability, CVE-2026-56164, was patched as part of Microsoft’s July 2026 Patch Tuesday updates. However, it was already being exploited in attacks before the fix was available. This vulnerability allows attackers to gain elevated privileges on a SharePoint server, potentially leading to further exploitation and data theft.
But this is not an isolated incident – CISA has also identified several other critical vulnerabilities in SharePoint that were patched by Microsoft’s July updates. These include CVE-2026-55040 and CVE-2026-58644, which can be exploited remotely to bypass security features and execute arbitrary code on a server.
The agency is particularly concerned about the risk of these vulnerabilities being exploited if organizations do not patch their systems in time. “These vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution (RCE) and post-exploitation activities,” CISA warns.
To mitigate the risk of these vulnerabilities being exploited, CISA recommends that organizations take several steps. First, they should apply Microsoft’s patches as soon as possible to address the known flaws. They should also ensure that their security products cover all SharePoint web applications, and monitor their servers for any signs of unusual activity.
In addition, CISA advises organizations to rotate IIS machine keys regularly, enable tailored logging, and restrict access to the administration interfaces. By taking these precautions, organizations can significantly reduce the risk of a successful attack on their SharePoint systems.
For those who are not familiar with SharePoint or its vulnerabilities, it’s worth noting that this platform is widely used by organizations for collaboration and document sharing. While it provides many benefits in terms of productivity and efficiency, it also poses significant risks if not properly secured. The recent exploits of these vulnerabilities serve as a reminder to all users of the importance of keeping software up-to-date and implementing robust security measures.
In summary, CISA’s warning about the exploited SharePoint vulnerabilities should be taken seriously by all organizations that use this platform. By patching their systems quickly and taking steps to mitigate the risk of exploitation, they can protect themselves from potential attacks and data breaches.
Source: SecurityWeek — 2026-07-15