VYPR
advisoryPublished Jul 15, 2026· Updated Jul 22, 2026· 12 sources

CISA Warns of Actively Exploited SharePoint Vulnerabilities

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding three actively exploited vulnerabilities in Microsoft SharePoint Server, urging organizations to apply patches and implement hardening measures.

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a stern warning to organizations running Microsoft SharePoint Server, highlighting three vulnerabilities that are currently being actively exploited in the wild. The alert emphasizes the need for immediate patching and enhanced security configurations to prevent further compromise.

The vulnerabilities in question include CVE-2026-32201, a spoofing flaw disclosed in March and confirmed by CISA to be under active exploitation since June. This is compounded by CVE-2026-45659, a critical remote code execution (RCE) vulnerability that, despite Microsoft initially assessing exploitation as "less likely," is now confirmed to be actively used in attacks. The third actively exploited flaw is CVE-2026-56164, a privilege escalation vulnerability that was part of Microsoft's latest Patch Tuesday release.

In addition to these three, CISA also flagged two other critical vulnerabilities from the recent Patch Tuesday: CVE-2026-55040 and CVE-2026-58644. While not yet confirmed as actively exploited, both have been labeled by Microsoft as having "Exploitation More Likely," suggesting a heightened risk of future attacks.

According to CISA, threat actors are chaining these vulnerabilities together to conduct post-exploitation activities. These activities include the theft of Internet Information Services (IIS) machine keys and the use of deserialization techniques, all aimed at establishing persistence on compromised systems and deploying malware. This sophisticated chaining of exploits underscores the severity of the threat and the potential for widespread impact.

The agency's warning echoes previous advisories, referencing an alert from August 2025 that cautioned against "ToolShell" attacks. In that instance, attackers were observed chaining CVE-2025-49706 and CVE-2025-49704 to gain access to SharePoint Servers, leading in some cases to the deployment of Warlock ransomware. While specific threat actor attribution was not provided for the current wave of attacks, Microsoft had previously linked ToolShell exploitation to Chinese nation-state actors.

To mitigate these risks, CISA strongly recommends that organizations apply all available Microsoft security patches for SharePoint Server. Furthermore, enabling the Antimalware Scan Interface (AMSI) for all SharePoint web applications is crucial for enhanced detection capabilities.

Additional hardening measures advised by CISA include conducting thorough threat hunting to identify any signs of existing intrusion, rotating IIS keys to prevent exposure, and blocking external access to SharePoint Central Administration. Robust and tailored logging configurations are also encouraged to aid in the detection of potential exploits and facilitate incident response.

The agency's proactive warning serves as a critical reminder for organizations to maintain vigilance and prioritize the security of their SharePoint environments, which often host sensitive internal data and are prime targets for attackers seeking to establish a foothold within corporate networks.

The Zero Day Initiative has published details on ZDI-26-413, a critical remote code execution vulnerability in Microsoft SharePoint, assigned CVE-2026-50522. This new advisory details a flaw in the handling of session security tokens, specifically the improper verification of cryptographic signatures, which can be exploited by unauthenticated attackers to execute code in the context of the service account. Microsoft has released an update to address this specific vulnerability, which was reported to the vendor on May 21, 2026.

This Tenable blog post provides a detailed FAQ addressing the active exploitation of three Microsoft SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) and two additional disclosed flaws (CVE-2026-55040, CVE-2026-58644), with CVE-2026-58644 confirmed as exploited. It elaborates on the specific post-exploitation activities observed, including IIS machine key extraction and malware deployment, and provides historical context on SharePoint Server exploitation and its presence in CISA's KEV catalog.

CISA has expanded its Known Exploited Vulnerabilities (KEV) Catalog to include two additional vulnerabilities affecting Fortinet FortiSandbox OS (CVE-2026-25089 and CVE-2026-39808) and one in Microsoft SharePoint (CVE-2026-58644). These additions underscore the ongoing threat posed by these specific vulnerabilities, with federal agencies now explicitly required to prioritize their remediation on publicly exposed assets.

This new report confirms that CVE-2026-58644, a critical deserialization vulnerability in Microsoft SharePoint, is now actively exploited in the wild. The vulnerability, which carries a CVSS score of 9.8, allows remote, authenticated attackers to execute arbitrary code on the server. CISA has added this CVE to its Known Exploited Vulnerabilities (KEV) catalog, mandating a three-day patching window for federal agencies.

CISA has officially added CVE-2026-58644, a critical remote code execution vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities (KEV) catalog. This designation mandates that federal agencies must apply available patches by July 19, 2026, underscoring the severity and active exploitation of this zero-day flaw.

The new article specifies that the vulnerability, CVE-2026-58644, is a critical flaw allowing unauthenticated remote code execution via unsafe deserialization (CWE-502). It highlights that exploitation could lead to network compromise, lateral movement, or further attacks, and mandates remediation for federal agencies under BOD 26-04.

This Rapid7 report provides specific technical details on CVE-2026-58644, a critical RCE vulnerability in on-premises Microsoft SharePoint Server. It confirms active exploitation and its addition to CISA's KEV catalog, urging immediate patching and highlighting specific Microsoft Defender and AMSI detection signatures that can identify exploitation attempts.

This new report from Resecurity details how attackers are chaining these vulnerabilities to achieve RCE, deploy web shells, and crucially, steal IIS machine keys. These stolen keys can enable persistent access even after the initial vulnerabilities are patched, and the attackers can also install malicious IIS modules to survive restarts and further compromise the network. The campaign can quickly move from initial web requests to deeper compromise of SharePoint, IIS, SQL Server, and Active Directory.

This new report provides further technical details on the active exploitation of Microsoft SharePoint vulnerabilities, specifically focusing on CVE-2026-50522, a critical RCE flaw with a CVSS score of 9.8. While CISA's alert covered multiple SharePoint vulnerabilities, this article highlights that CVE-2026-50522 is likely being exploited in the wild due to its unauthenticated nature, distinguishing it from the previously confirmed exploitation of CVE-2026-58644.

This new report details that CVE-2026-50522, a critical SharePoint RCE vulnerability rated 9.8 CVSS, is now under active exploitation in the wild. Researchers have observed threat actors stealing machine keys for persistent access and deploying .NET deserialization payloads, following the release of a public proof-of-concept exploit. Microsoft had previously patched this flaw as part of its July 2026 Patch Tuesday updates.

This new report details active exploitation of CVE-2026-50522, a critical RCE vulnerability in Microsoft SharePoint, with attackers specifically targeting and stealing IIS machine keys to establish persistent access. Exploitation attempts were observed within hours of public exploit code release, indicating a rapid response from threat actors to this newly disclosed flaw.

Synthesized by Vypr AI