CISA Urges Immediate Patching of Actively Exploited SharePoint Vulnerabilities
CISA warns that attackers are actively exploiting three serious vulnerabilities in Internet-exposed, on-premises Microsoft SharePoint Server instances. These flaws, tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, affect all supported self-hosted versions of SharePoint Server. Attackers use them to bypass authentication, execute remote code, and establish persistence on compromised systems.
According to the security group Shadowserver, nearly 10,000 SharePoint servers are currently exposed online, with over 800 remaining unpatched against the known vulnerabilities. Microsoft has released patches for these actively exploited flaws along with two additional vulnerabilities that, while not yet exploited in the wild, present attractive targets for future attacks.
CISA urges administrators to apply the latest Microsoft patches immediately and verify their successful installation. The agency also recommends enabling AMSI integration for SharePoint web applications, rotating IIS machine keys after remediating any intrusion artifacts, and restricting direct internet exposure of SharePoint servers whenever possible to minimize risk.