North America
Microsoft SharePoint
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned organizations about several Microsoft SharePoint vulnerabilities that are actively being exploited or pose significant security risks. The advisory highlights the need for organizations using on-premises SharePoint Server to promptly assess their exposure and apply available security updates.
CISA stated that it is aware of active exploitation of the following vulnerabilities, which enable threat actors to gain unauthorized access to on-premises SharePoint Server instances.
- CVE-2026-32201: An improper input validation vulnerability that allows an attacker to perform spoofing over a network.
- CVE-2026-45659: A remote code execution vulnerability involving the deserialization of untrusted data that allows an authorized attacker to execute code over a network.
- CVE-2026-56164: A missing authentication for a critical function vulnerability in Microsoft Office SharePoint that allows an attacker to elevate privileges over a network.
- CVE-2026-58644: A remote code execution vulnerability that allows an unauthorized attacker to execute code over a network.
- CISA has also identified CVE-2026-55040, a newly disclosed vulnerability that is not yet known to have been exploited but poses a potential risk if left unpatched. The weakness involves improper authentication in Microsoft Office SharePoint, allowing an unauthorized attacker to bypass a network security feature.
The latest advisory reflects a steady stream of new SharePoint vulnerabilities, including both pre-disclosure zero-day exploitation and longer-tail n-day exploitation.
How it could affect your business
The continued discovery and exploitation of these flaws underscore the importance of timely patching and ongoing monitoring for organizations that rely on on-premises SharePoint environments. CISA advises security teams to rotate Internet Information Services (IIS) machine keys and check for signs of compromise, including machine key harvesters. Organizations should also avoid exposing SharePoint directly to the internet and block external access to SharePoint Central Administration. Here’s a SharePoint hardening guide from Microsoft to strengthen your SharePoint security posture.
