The US Cybersecurity and Infrastructure Security Agency (CISA) has confirmed attackers are actively
exploiting four security flaws in on-premises Microsoft SharePoint Server to break in, run their own
code, and hide inside networks. All supported versions (Subscription Edition, 2019, and 2016) are
affected, and attackers steal server keys that can let them return even after patching. Patch now, check
servers for signs of compromise, and remove any attacker footholds before rotating stolen keys.
1.Vulnerability Details
CISA reports active exploitation of four SharePoint Server vulnerabilities that give attackers unauthorised access to on premises instances. Intrusions establish remote code execution, then move into post-exploitation activity: stealing Internet Information Services (IIS) machine keys and performing deserialisation techniques to gain persistence and deploy malware. All four exploited CVEs now sit in CISA’s Known Exploited Vulnerabilities (KEV) Catalog. A fifth CVE, patched in the same July 2026 Microsoft update, is not yet known to be exploited.
- CVE-2026-32201: Spoofing flaw exploited in attacks as a zero-day and patched by Microsoft in April 2026. Added to the KEV Catalog on 14 April 2026.
- CVE-2026-45659: Code execution flaw patched in May 2026 via an out-of-band security update. Added to the KEV Catalog on 1 July 2026.
- CVE-2026-56164: Elevation of privilege flaw exploitable remotely without authentication, fixed in Microsoft’s July 2026 Patch Tuesday. Added to the KEV Catalog on 14 July 2026.
- CVE-2026-58644: Critical flaw allowing remote security feature bypass and arbitrary code execution, fixed in July Exploitation confirmed; added to the KEV Catalog on 16 July 2026.
- CVE-2026-55040: Newly disclosed flaw fixed in July 2026, not yet known to be exploited. Microsoft identifies it as a potential risk if left unpatched.
2. Affected Products
- Microsoft SharePoint Server Subscription Edition (on-premises)
- Microsoft SharePoint Server 2019 (on-premises)
- Microsoft SharePoint Server 2016 (on-premises)
3. Observed Attacker Activity
- Attack chain: Attackers gain unauthorised access to internet-reachable SharePoint Servers, establish remote code execution, steal IIS machine keys, and use deserialisation techniques for persistence and malware deployment.
- Machine-key theft: CISA warns that intrusion artifacts left in place, including machine-key harvesters, can let attackers steal rotated IIS machine keys again. Hunt and remediate before rotating keys.
- Microsoft response: Microsoft has blocked observed exploitation attempts on the SharePoint Server Subscription signout vector and published AMSI and Defender detection signatures covering 2016, 2019, and Subscription Edition.
4. Recommendations
- Apply Microsoft’s July 2026 SharePoint updates covering all five CVEs, verify installation completed successfully, and shorten patching cycles where possible.
- Verify that AMSI integration is enabled for each SharePoint web application. Follow Microsoft’s Configure AMSI integration with SharePoint Server guidance (https://learn.microsoft.com/en-us/sharepoint/se curity-for-sharepoint-server/configure-amsi-integration) to ensure proper configuration and select the “Full Mode” option for the Request Body Scan Mode, where feasible. When compromise is expected, use the following AMSI and Microsoft Defender Antivirus (MDAV) detections, and implement your organization’s incident response plan for any positive detections: AMSI: Exploit:Script/SuspSignoutReqBody.A – request body scanning; SharePoint Server Subscription only; Microsoft has blocked observed attempts. AMSI: Exploit:Script/ToolPaneAuthBypass.A – request header scanning; SharePoint Server 2016, 2019, and Subscription Edition. AMSI: Exploit:Script/ToolPaneAuthBypass.C – RCE coverage; SharePoint Server 2016, 2019, and Subscription Edition. MDAV: Backdoor:MSIL/LeakFang.A!dha – post-exploitation activity alert involving IIS-protected secrets.
- Find every on-premises SharePoint Server (2016, 2019, Subscription Edition) and review telemetry for webshells, anomalous requests, suspicious worker-process activity, and machine-key access.
- Hunt for and remove intrusion artifacts, including machine-key harvesters, before rotating IIS machine keys; treat any AMSI or Defender detection hit as an incident.
- Remove direct internet exposure of SharePoint Servers, place servers behind a Layer 7 reverse proxy and block external access to SharePoint Central Administration.
- Review Microsoft’s SharePoint Server security-hardening guidance (https://learn.microsoft.com/en-us/ sharepoint/security-for-sharepoint-server/security-hardening) for role-specific ports, services, and Web.config settings.
5. Sources
- https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-ne
w-exploitations - https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-sharepoint-vulnerab
ilities/
Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn
No related posts found.