CISA warns that attackers are actively exploiting three serious vulnerabilities in Internet-exposed, on-premises Microsoft SharePoint Server instances. These flaws, tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, affect all supported self-hosted versions of SharePoint Server. Attackers use them to bypass authentication, execute remote code, and establish persistence on compromised systems.
According to