{"id":63451,"date":"2026-07-15T08:07:30","date_gmt":"2026-07-15T12:07:30","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=63451"},"modified":"2026-07-15T08:07:30","modified_gmt":"2026-07-15T12:07:30","slug":"cisa-sharepoint-patching","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/cisa-sharepoint-patching\/","title":{"rendered":"CISA Orders Patching of Actively Exploited SharePoint Flaws"},"content":{"rendered":"<p>The U.S. Cybersecurity and Infrastructure Security Agency (<a href=\"https:\/\/overcentral.com\/en\/cisa-active-exploitation-lantronix-ubiquiti\/\" title=\"CISA Confirms Active Exploitation of Lantronix and Ubiquiti Flaws\" data-iacss-internal=\"1\">CISA<\/a>) has issued an urgent directive ordering federal agencies to patch three actively exploited vulnerabilities in <a href=\"https:\/\/www.microsoft.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Microsoft<\/a> SharePoint Server, warning that attackers are using these flaws to bypass authentication, achieve <a href=\"https:\/\/overcentral.com\/en\/airdrop-quick-share-flaws\/\" title=\"Six AirDrop and Quick Share flaws expose 5 billion devices\" data-iacss-internal=\"1\">remote code execution<\/a>, and establish persistent access on compromised systems. The vulnerabilities, cataloged as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, affect all supported self-hosted versions of SharePoint Server, including the Subscription Edition, which operates under a continuous update model. CISA confirmed that these flaws are being actively exploited against Internet-exposed on-premises SharePoint instances, making immediate patching critical for organizations across the public and private sectors.<\/p>\n<h2>Attack Chain and Post-Exploitation Activity<\/h2>\n<p>According to a Tuesday advisory from CISA, the attack chain leverages the three vulnerabilities to gain initial access and then escalate privileges. Once inside a network, attackers have been observed stealing Internet Information Services (IIS) machine keys. This stolen credential material allows them to impersonate legitimate systems and deploy malware, effectively establishing a persistent foothold within the victim\u2019s environment. The exploitation is not merely theoretical; CISA has clear evidence that these techniques are being used in live campaigns against unpatched servers.<\/p>\n<h2>Additional Vulnerabilities Added to the Watch List<\/h2>\n<p>Beyond the three actively exploited flaws, CISA also flagged two additional SharePoint Server vulnerabilities\u2014CVE-2026-55040 and CVE-2026-58644\u2014which Microsoft patched on the same Tuesday update cycle. While CISA tagged these as attractive targets for attackers due to their potential impact, there is currently no evidence of them being exploited in the wild. Nonetheless, the agency recommends prioritizing their remediation as part of a proactive security posture.<\/p>\n<h2>Scope of Exposure: Unpatched Servers Remain a Global Risk<\/h2>\n<p>The internet security monitoring group Shadowserver is tracking nearly 10,000 Internet-exposed Microsoft SharePoint servers worldwide. Of these, over 800 are confirmed to be unpatched against both CVE-2026-32201 and CVE-2026-45659. Shadowserver\u2019s data does not provide a clear count of servers vulnerable to CVE-2026-56164, nor does it distinguish genuine production systems from decoy honeypots, meaning the actual attack surface could be larger than the confirmed figures suggest. This widespread exposure underscores the urgency of the patching directive, particularly for organizations in the US, UK, Australia, and Canada where SharePoint is a staple of enterprise collaboration.<\/p>\n<h2>What is the deadline for federal agencies to patch these SharePoint vulnerabilities?<\/h2>\n<p>Federal civilian executive branch agencies are required to secure their SharePoint servers against CVE-2026-56164 by July 17 under Binding Operational Directive (BOD) 26-04. If mitigations cannot be applied within that timeframe, the affected servers must be disconnected from the network. This deadline makes the current window for action extremely short. Since November 2021, CISA has cataloged 11 Microsoft SharePoint vulnerabilities that have been exploited in attacks, with seven of those tied directly to ransomware operations, highlighting the persistent threat this platform faces.<\/p>\n<h2>Recommended Hardening and Detection Measures<\/h2>\n<p>CISA has provided a detailed set of hardening measures for security teams to implement immediately. The primary step is to apply Microsoft\u2019s latest patches and verify their successful installation. To detect active compromise, organizations should enable the Windows Antimalware Scan Interface (AMSI) integration for SharePoint web applications and ensure <a href=\"https:\/\/overcentral.com\/en\/microsoft-defender-patch-disk-exhaustion\/\" title=\"Microsoft Defender patch risks filling Windows hard drives\" data-iacss-internal=\"1\">Microsoft Defender<\/a> Antivirus (MDAV) is active with updated detections. Furthermore, security teams should shorten their patching cycles to reduce the window of exposure for future vulnerabilities.<\/p>\n<p>Post-patching, the agency recommends a rigorous cleanup process. Teams must hunt for and remediate any intrusion artifacts\u2014such as backdoors or unauthorized accounts\u2014before rotating the stolen IIS machine keys. Establishing tailored logging is also critical to monitor for anomalous post-exploitation activity. Where possible, organizations should avoid exposing SharePoint servers directly to the internet. If exposure is unavoidable, systems should be placed behind a Layer 7 reverse proxy or a similar application-layer security control to filter malicious traffic. Access to SharePoint Central Administration must be blocked from external networks, and farm and database communication should be restricted to only the required systems.<\/p>\n<h2>What Affected Organizations Should Do Now<\/h2>\n<p>For any organization running an on-premises SharePoint Server, the immediate action is to review the complete list of vulnerabilities mentioned in this advisory and apply the corresponding patches from Microsoft without delay. After patching, conduct a thorough forensic review of the server logs for signs of unauthorized access, particularly looking for unusual authentication patterns or unexpected outbound connections. If any evidence of compromise is found, immediately isolate the affected server and engage an incident response team. As a general security practice, evaluate whether your SharePoint deployment can be moved behind a zero-trust architecture or a reputable cloud-based web application firewall (WAF) that provides Layer 7 protection, which can help mitigate future threats even if patching cycles lag. The exploitation of these vulnerabilities demonstrates that on-premises infrastructure remains a high-value target, and proactive hardening is the only reliable defense.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive ordering federal agencies to patch three actively exploited vulnerabilities in Microsoft SharePoint Server, warning that attackers are using these flaws to bypass authentication, achieve remote code execution, and establish persistent access on compromised systems. The vulnerabilities, cataloged as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":74595,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/iili.io\/CMHpELF.jpg","fifu_image_alt":"CISA Orders Patching of Actively Exploited SharePoint Flaws","footnotes":""},"categories":[349],"tags":[],"class_list":["post-63451","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/iili.io\/CMHpELF.jpg","fifu_image_alt":"CISA Orders Patching of Actively Exploited SharePoint Flaws","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/63451","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=63451"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/63451\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/74595"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=63451"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=63451"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=63451"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}