CISA Mandates Patching for SharePoint
Federal agencies must secure SharePoint servers against active exploitation of three critical remote code execution vulnerabilities.
Security teams managing on-premises infrastructure are facing an urgent directive to address active threats targeting Microsoft SharePoint Server. The U.S. Cybersecurity and Infrastructure Security Agency recently issued a warning concerning three specific vulnerabilities currently being leveraged by attackers to compromise Internet-exposed systems.
Technical Scope of the Attacks
The flaws, cataloged as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, impact all supported versions of self-hosted SharePoint Server. This includes the SharePoint Server Subscription Edition, which utilizes a continuous update model. Attackers are reportedly using these entry points to bypass authentication mechanisms and gain remote code execution capabilities.
Once inside a system, adversaries perform post-exploitation activities, such as harvesting Internet Information Services machine keys. These keys are then used to maintain persistence, allowing for the subsequent deployment of malware across compromised environments.
Monitoring the Exposed Infrastructure
According to tracking data from the Internet security watchdog group Shadowserver, nearly 10,000 Microsoft SharePoint servers are currently exposed to the public internet. Among that total, over 800 servers remain unpatched against the specific CVE-2026-32201 and CVE-2026-45659 vulnerabilities.
- Nearly 10,000 Internet-exposed Microsoft SharePoint servers are currently tracked.
- Over 800 servers are known to be unpatched against CVE-2026-32201 and CVE-2026-45659.
- Federal agencies are required by Binding Operational Directive 26-04 to secure systems affected by CVE-2026-56164 by July 17.
- CISA has flagged 11 total Microsoft SharePoint vulnerabilities exploited in attacks since November 2021.
Hardening and Remediation Requirements
CISA is mandating that federal agencies address the risks associated with CVE-2026-56164 by July 17 or face the requirement to discontinue the use of affected servers. Beyond immediate patching, the agency recommends several official SharePoint Server security-hardening guidance steps, including the use of Microsoft Defender Antivirus and the Windows Antimalware Scan Interface.
Defenders are also encouraged to hunt for intrusion artifacts and rotate IIS machine keys to ensure attackers have not already established a foothold. Where direct internet exposure is unavoidable, the agency suggests placing servers behind a Layer 7 reverse proxy to provide an additional application-layer security barrier.
Broader Implications for Security Teams
The reliance on on-premises software continues to create significant maintenance burdens for organizations that fail to keep pace with rapid patching cycles. For many, the necessity of maintaining older, complex enterprise systems often leads to visibility gaps, as evidenced by the high volume of exposed servers identified by security researchers. If organizations cannot guarantee the integrity of their internet-facing infrastructure, moving sensitive services away from public accessibility remains the most reliable strategy to prevent unauthorized access and long-term persistence by malicious actors.
Sources
- BleepingComputer Original source
- official SharePoint Server security-hardening guidance Also reporting
Continue Reading
Tech Giants Warn AI Attack Window Is Closing
Over 100 firms, including OpenAI and Google, urge action before AI attacks hit critical services hard.
First 24 Hours: Responding to an AI Agent Incident
What to do when an autonomous agent acts beyond its bounds, hour by hour.
GiveWP flaw opens server to unauthenticated takeover
A critical GiveWP plugin bug chains three issues, letting attackers run commands on WordPress servers with no account needed.