Skip to content

CISA Urges Immediate SharePoint Hardening

In a nutshell: Three actively exploited SharePoint vulnerabilities (CVE-2026-332201, CVE-2026-45659, CVE-2026-56164) require immediate patches and network segmentation, as a single compromised SharePoint server can become a gateway for widespread infrastructure compromise.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has called on organizations to immediately harden their Microsoft SharePoint installations following confirmation of three actively exploited vulnerabilities in the on-premises collaboration platform. The flaws have been added to CISA’s Catalog of Known Exploited Vulnerabilities (KEV).

CISA has issued a directive demanding immediate remediation of three vulnerabilities in Microsoft SharePoint Server: CVE-2026-332201, CVE-2026-45659, and CVE-2026-56164. These security gaps are already being exploited by attackers in the wild and have therefore been added to the KEV list. Administrators are urged to deploy updates, take Microsoft’s mitigation guidance into account, and assume that internet-facing SharePoint installations represent a preferred attack target.

Particularly critical is CVE-2026-56164, an elevation-of-privilege vulnerability with a CVSS score of 5.3. Although this score appears moderate at first glance, the flaw can be exploited remotely and without authentication—in practice, it is significantly more dangerous than the rating suggests. Microsoft has released security updates for supported SharePoint versions and recommends enabling the Antimalware Scan Interface (AMSI) to detect malicious requests. CISA additionally advises searching for indicators of compromise and rotating SharePoint machine keys, as patches alone may not fully remediate already-compromised servers.

CVE-2026-45659 is a deserialization vulnerability that enables remote code execution (RCE). Although Microsoft classified it in May as “less likely to be exploited,” it is now actively being attacked. CVE-2026-32201 is an input validation flaw that allows network-based spoofing and is also being exploited in the wild. CISA points out that attackers are increasingly targeting older, known vulnerabilities (N-Days) rather than exclusively zero-days.

For security leaders, the issue is not solely about patch velocity: the window between disclosure and exploitation continues to shrink. A more realistic assumption is therefore that systems will be compromised. The central question is how tightly network segmentation is configured and how much business operations an attacker can disrupt from a single compromised SharePoint server. Segmentation, not just patch speed, should be a core component of defensive strategy—it is a control mechanism that organizations can enforce independently. CISA has set a three-day deadline for federal agencies to remediate CVE-2026-56164 under Binding Operational Directive (BOD) 22-01.


Source: www.csoonline.com · Published July 16, 2026
Lumi AI News — AI-assisted curation according to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: