Skip to content

CISA Warns of Actively Exploited SharePoint Security Vulnerabilities

In a nutshell: Three SharePoint security vulnerabilities are currently being exploited at scale and require immediate patches.

The U.S. agency CISA warns that attackers are actively exploiting three security vulnerabilities in internet-accessible SharePoint on-premises server instances.

On Tuesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a warning about three security vulnerabilities being exploited in SharePoint Server systems with direct internet access. The affected systems are on-premises installations, not the cloud variant SharePoint Online.

For CISOs, this represents an elevated risk if the affected SharePoint Server versions are connected to the internet without network segmentation or firewalls. Attackers are actively exploiting these vulnerabilities to gain system access—a typical entry point for larger compromises.

Patching SharePoint servers should be the highest priority. Organizations with on-premises deployments should immediately review their systems, identify affected versions, and apply available patches. In parallel, controls should be reviewed to determine whether these systems truly require internet access or whether they can be operated behind additional security layers.


Source: www.bleepingcomputer.com · Published 15 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.

Share on: