CISA Urges SharePoint Hardening After New Exploitations

CISA is warning organizations of active exploitation targeting multiple vulnerabilities in Microsoft SharePoint Server environments. Attackers are exploiting CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 to gain unauthorized access to supported SharePoint Server versions, including Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Successful exploitation allows threat actors to achieve remote code execution (RCE) and conduct post-exploitation activities, including stealing Internet Information Services (IIS) machine keys, leveraging deserialization techniques to establish persistence, and deploying malware. Organizations should closely monitor SharePoint environments for indicators of compromise and suspicious activity.

Microsoft has also disclosed two additional vulnerabilities—CVE-2026-55040 and CVE-2026-58644—that are not currently known to be exploited but should be patched promptly to reduce future risk.

This advisory is especially relevant for organizations that own or operate Healthcare and Public Health infrastructure. These HPH entities rely on SharePoint as a secure, centralized platform for managing sensitive information, supporting staff collaboration, and streamlining operational workflows. Because the sector deals with highly sensitive data, SharePoint deployments are typically customized to meet strict security and regulatory standards.

Recommended Actions:

  • Apply the latest Microsoft security updates via the Microsoft 365 Roadmap or Office Release Notes pages immediately and verify successful installation.
  • Enable Antimalware Scan Interface (AMSI) integration for all SharePoint web applications and, where possible, configure Full Mode request body scanning.
  • Monitor Microsoft Defender Antivirus and AMSI alerts for signs of exploitation or post-compromise activity.

For more information, read CISA’s bulletin.