CISA warns on three SharePoint flaws
CISA says three SharePoint Server on-premises flaws are being actively exploited and urges patching plus tighter hardening.
CISA warned that three vulnerabilities in Microsoft SharePoint Server on-premises, tracked as CVE-2026-32201, CVE-2026-45659 and CVE-2026-56164, are being actively exploited. The agency said threat actors are using them to gain unauthorized access, steal IIS machine keys, and maintain persistence through deserialization and malware deployment.
Active exploitation in SharePoint Server
CISA has issued an official alert over active exploitation of three vulnerabilities in Microsoft SharePoint Server on-premises, tracked as CVE-2026-32201, CVE-2026-45659 and CVE-2026-56164. According to the agency, threat actors are using the flaws to gain unauthorized access to local instances, steal IIS machine keys, and maintain persistence through deserialization techniques and malware deployment.
The warning adds all three CVEs to the Known Exploited Vulnerabilities catalog, placing the case under a federal priority response. CISA also told organizations to report any incident or anomalous activity tied to SharePoint to its 24/7 Operations Center.
What each CVE does
Threadlinqs Intelligence described CVE-2026-32201 as an input validation flaw that enables spoofing and authentication bypass, with a CVSS score of 6.5. For CVE-2026-45659, the technical briefing places it as an insecure deserialization issue that allows remote code execution, with a CVSS score of 8.8 and CWE-502. CVE-2026-56164 was characterized as a missing authentication flaw in a critical function, with a CVSS score of 5.3 and CWE-1220.
Computerworld reported that CISA gave agencies in the Federal Civilian Executive Branch three days to remediate CVE-2026-56164 under Binding Operational Directive 22-01. The outlet added that, although the flaw carries a CVSS score of 5.3, it can be exploited remotely and without authentication, making it more dangerous in enterprise environments that expose SharePoint to the internet.
Penligent AI agreed that CVE-2026-56164 can be exploited by an attacker with no prior account, no user interaction and low attack complexity. It also said Microsoft marked exploitation as detected and that CISA added the flaw to the KEV catalog on July 14, 2026. The explicit scope includes SharePoint Server Subscription Edition, SharePoint Server 2019 and SharePoint Enterprise Server 2016, while SharePoint Online does not use these on-premises update packages.
Additional defensive steps
CISA recommended steps beyond patching. These include blocking external access to SharePoint Central Administration, limiting farm and database communications to required systems only, and reviewing Microsoft hardening guidance for ports, services and Web.config settings.
Cybersecurity Dive added that the agency is also urging organizations to enable Antimalware Scan Interface integration, rotate IIS machine keys, and look for intrusion artifacts such as machine key harvesters. DugganUSA said CISA describes scenarios in which attackers steal those keys and use deserialization to establish persistence before deploying malware.
Smarttech247 added controls for SharePoint environments, including blocking external access to Central Administration, deploying IDS or IPS on servers, setting up specific logging to detect web shells and machine key access, and monitoring suspicious processes and outbound connections.
Scope and technical context
DugganUSA confirmed that affected versions include SharePoint Server Subscription Edition, SharePoint Server 2019 and SharePoint Server 2016, and stressed that chaining the flaws is already happening in production environments. The same material said Microsoft considers CVE-2026-56164 to be exploited in the wild.
Threadlinqs linked the campaign to MITRE ATT&CK techniques including T1595, Active Scanning, T1190, Exploit Public-Facing Application, T1078, Valid Accounts, and T1203, Exploitation for Client Execution, suggesting tactical use of the flaws during reconnaissance, intrusion and malicious payload execution.
Penligent AI also warned that patching CVE-2026-56164 only blocks future exploitation, but does not remove persistence that may already have been established before remediation. It recommended identifying on-premises farms, preserving evidence, limiting exposure, installing the full July update set, applying the SharePoint configuration update, verifying fixed builds across all nodes, validating AMSI and endpoint protection, and investigating the pre-patch window for signs of compromise.
Sources
- CISA warns that multiple vulnerabilities in SharePoint are being exploitedcybersecuritydive.com· Cybersecurity Dive
- CISA warns of active exploitation of three critical SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164)cve.tools· CVE.tools
- CVE-2026-56164: SharePoint Missing Authentication for Critical Functionpenligent.ai· Penligent AI
- CISA urges immediate SharePoint hardening as exploits mountcomputerworld.com· Computerworld
- CISA Warns of Active Exploitation of Three Microsoft SharePoint Server Vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164)intel.threadlinqs.com· Threadlinqs Intelligence
- CISA Says Three SharePoint Flaws Are Being Chained Right Now. We Wrote the Hunt for One of Them in May.dugganusa.com· DugganUSA
- Critical Patches Issued for Microsoft Products, July 14, 2026cisecurity.org· Center for Internet Security
- CISA Urges SharePoint Hardening After New Exploitationscisa.gov· Cybersecurity and Infrastructure Security Agency (CISA)
- Martes de parches de Microsoft de julio de 2026: 622 CVEssplashtop.com· Splashtop
- Microsoft Patch Tuesday | Threat Intel Reports – July 2026smarttech247.com· Smarttech247



