CISA | Alerts
Follow
CISA Urges SharePoint Hardening After New Exploitations
CISA is aware of active exploitation of vulnerabilities in on-premises SharePoint Server instances, specifically CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, which enable cyber threat actors to gain unauthorized access. These vulnerabilities affect all supported on-premises SharePoint Server versions and involve establishing remote code execution and post-exploitation activities. Organizations should monitor affected SharePoint Servers closely for any signs of exploitation or unusual activity. CISA urges organizations to detect and remediate potential compromises by implementing recommendations such as applying the latest patches and security updates from Microsoft. Additionally, CISA recommends verifying that Antimalware Scan Interface integration is enabled for each SharePoint web application and using specific AMSI and Microsoft Defender Antivirus detections. Organizations should also implement SharePoint Server hardening measures, including rotating IIS machine keys, establishing tailored logging mechanisms, and avoiding exposing SharePoint Servers directly to the internet. CISA added the vulnerabilities to its Known Exploited Vulnerabilities Catalog and urges users and administrators to review the Alert and apply necessary updates. The agency also recommends reporting incidents or anomalous activity to CISA via its 24/7 Operations Center. CISA may update this Alert to reflect new guidance issued by CISA or other parties, and the information in this report is being provided for informational purposes only. Overall, CISA's guidance aims to help organizations protect themselves against potential cyber threats by taking proactive measures to secure their SharePoint Server instances.