Update July 16, 2026:
CISA has updated this Alert to reflect the addition of CVE-2026-58644 to its Known Exploited Vulnerabilities (KEV) Catalog on July 16, 2026.
CISA is aware of active exploitation of vulnerabilities CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644, enabling cyber threat actors to gain unauthorized access to on-premises SharePoint Server instances. These vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution (RCE) and post-exploitation activities, such as stealing Internet Information Services (IIS) machine keys and performing deserialization techniques, to gain persistence and deploy malware. Organizations should monitor affected SharePoint Servers closely for any signs of exploitation or unusual activity.
Additionally, the following newly disclosed CVE is not yet known to have been exploited, but Microsoft has identified it as posing a potential risk if left unpatched:
CISA urges organizations to detect and remediate a potential compromise by implementing the following recommendations:
Exploit:Script/SuspSignoutReqBody.A – request body scanning; SharePoint Server Subscription only; Microsoft has blocked observed attempts.Exploit:Script/ToolPaneAuthBypass.A – request header scanning; SharePoint Server 2016, 2019, and Subscription Edition.Exploit:Script/ToolPaneAuthBypass.C – RCE coverage; SharePoint Server 2016, 2019, and Subscription Edition.Backdoor:MSIL/LeakFang.A!dha – post-exploitation activity alert involving IIS-protected secrets.In addition, CISA recommends that organizations implement the following SharePoint Server hardening measures:
Web.config settings.CISA urges users and administrators to review the Alert UPDATE: Microsoft Releases Guidance on Exploitation of SharePoint Vulnerabilities and apply necessary updates.
CISA added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2026-32201 on April 14, 2026; CVE-2026-45659 on July 1, 2026; CVE-2026-56164 on July 14, 2026; and CVE-2026-58644 on July 16, 2026.
Note: CISA may update this Alert to reflect new guidance issued by CISA or other parties.
Organizations should report incidents or anomalous activity to CISA via CISA’s 24/7 Operations Center at contact@cisa.dhs.gov or 1-844-Say-CISA (1-844-729-2472).
The information in this report is being provided “as is” for informational purposes only. CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA.
Microsoft contributed to this Alert.
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on…
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on…
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on…
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on…
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on…
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on…
This website uses cookies.