Breaking
SecurityDeveloping Story

CISA Mandates Patching for SharePoint

Federal agencies must secure SharePoint servers against active exploitation of three critical remote code execution vulnerabilities.

··1 month ago·2 min read
a bunch of wires that are connected to a server
Photo by Lightsaber Collection on Unsplash

Security teams managing on-premises infrastructure are facing an urgent directive to address active threats targeting Microsoft SharePoint Server. The U.S. Cybersecurity and Infrastructure Security Agency recently issued a warning concerning three specific vulnerabilities currently being leveraged by attackers to compromise Internet-exposed systems.

Technical Scope of the Attacks

The flaws, cataloged as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, impact all supported versions of self-hosted SharePoint Server. This includes the SharePoint Server Subscription Edition, which utilizes a continuous update model. Attackers are reportedly using these entry points to bypass authentication mechanisms and gain remote code execution capabilities.

Once inside a system, adversaries perform post-exploitation activities, such as harvesting Internet Information Services machine keys. These keys are then used to maintain persistence, allowing for the subsequent deployment of malware across compromised environments.

Monitoring the Exposed Infrastructure

According to tracking data from the Internet security watchdog group Shadowserver, nearly 10,000 Microsoft SharePoint servers are currently exposed to the public internet. Among that total, over 800 servers remain unpatched against the specific CVE-2026-32201 and CVE-2026-45659 vulnerabilities.

  • Nearly 10,000 Internet-exposed Microsoft SharePoint servers are currently tracked.
  • Over 800 servers are known to be unpatched against CVE-2026-32201 and CVE-2026-45659.
  • Federal agencies are required by Binding Operational Directive 26-04 to secure systems affected by CVE-2026-56164 by July 17.
  • CISA has flagged 11 total Microsoft SharePoint vulnerabilities exploited in attacks since November 2021.

Hardening and Remediation Requirements

CISA is mandating that federal agencies address the risks associated with CVE-2026-56164 by July 17 or face the requirement to discontinue the use of affected servers. Beyond immediate patching, the agency recommends several official SharePoint Server security-hardening guidance steps, including the use of Microsoft Defender Antivirus and the Windows Antimalware Scan Interface.

Defenders are also encouraged to hunt for intrusion artifacts and rotate IIS machine keys to ensure attackers have not already established a foothold. Where direct internet exposure is unavoidable, the agency suggests placing servers behind a Layer 7 reverse proxy to provide an additional application-layer security barrier.

Broader Implications for Security Teams

The reliance on on-premises software continues to create significant maintenance burdens for organizations that fail to keep pace with rapid patching cycles. For many, the necessity of maintaining older, complex enterprise systems often leads to visibility gaps, as evidenced by the high volume of exposed servers identified by security researchers. If organizations cannot guarantee the integrity of their internet-facing infrastructure, moving sensitive services away from public accessibility remains the most reliable strategy to prevent unauthorized access and long-term persistence by malicious actors.

#sharepoint#cisa#vulnerability#cybersecurity#patching

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories