At a glance: Three SharePoint vulnerabilities (CVE-2026-332201, CVE-2026-45659, CVE-2026-56164) are actively exploited in the wild — patching is necessary, but network segmentation is critical to limit impact.
The US Cybersecurity and Infrastructure Security Agency (CISA) is calling on organisations to immediately harden Microsoft SharePoint On-Premises. Three vulnerabilities are currently being actively exploited in attacks.
CISA has added three vulnerabilities in Microsoft SharePoint Server to its “Known Exploited Vulnerabilities” (KEV) catalogue because all three are currently being exploited by attackers. The affected vulnerabilities are CVE-2026-332201, CVE-2026-45659, and CVE-2026-56164. The agency is urging administrators to patch vulnerable servers, review Microsoft’s mitigation guidance, and assume that internet-facing SharePoint instances serve attackers as initial attack vectors into enterprise environments.
The latest vulnerability, CVE-2026-56164, is a privilege escalation flaw with a CVSS score of 5.3, but can be exploited remotely without authentication — a practical threat that its severity rating does not fully capture. Microsoft has released security updates for supported SharePoint versions and recommends enabling Antimalware Scan Interface (AMSI) integration to detect malicious requests. For CVE-2026-45659 (a deserialization vulnerability with remote code execution that Microsoft originally rated as “exploitation less likely”) and CVE-2026-32201 (network-based spoofing due to improper input validation), CISA confirms active exploitation. Attackers are increasingly leveraging known N-day vulnerabilities rather than relying exclusively on newly discovered zero-days.
CISA recommends that organisations search for indicators of compromise, rotate SharePoint machine keys, and follow Microsoft’s incident response guidance — a warning that patching alone may not be sufficient to remove already established attacker persistence.
For CISOs, the core message is an architectural paradigm: not patching speed, but network segmentation as the primary control. A compromised SharePoint instance with a direct path to domain controllers, backups, and file shares quickly escalates an IT incident into a business crisis. Segmentation breaks this lateral movement chain. Under Binding Operational Directive (BOD) 22-01, Federal Civilian Executive Branch (FCEB) agencies must remediate CVE-2026-56164 within three days.
Source: www.csoonline.com · Published 16 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.