news.mlab.sh
Back to the feed
vulnerability

CISA Urges SharePoint Hardening After New Exploitations

High
Summary

The Cybersecurity and Infrastructure Security Agency (CISA) is warning organizations with on-premises SharePoint Server instances (versions 2016, 2019, and Subscription Edition) about active exploitation of vulnerabilities, leading to potential remote code execution and data theft. CISA urges immediate patching and hardening measures, including AMSI integration and SharePoint Server security configurations, to mitigate the risk of compromise and ongoing malicious activity. Microsoft has contributed to this alert.

The Cybersecurity and Infrastructure Security Agency (CISA) is alerting organizations running on-premises SharePoint Server to a heightened risk of exploitation. Several vulnerabilities – CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 – are currently being actively exploited, enabling cyber threat actors to gain unauthorized access and potentially steal sensitive information. These vulnerabilities allow for remote code execution and post-exploitation activities, such as harvesting IIS machine keys. CISA recommends that organizations immediately apply the latest patches and security updates from Microsoft to address these issues.

Microsoft has identified these vulnerabilities as posing a significant risk and has released guidance to help organizations mitigate the threat. Specifically, CISA recommends enabling AMSI integration, configuring SharePoint Server security hardening measures, and implementing tailored logging mechanisms to detect and monitor exploitation attempts.

Key recommendations include:

  • Apply the latest patches and security updates from Microsoft.
  • Enable AMSI integration, configuring the Request Body Scan Mode to ‘Full Mode’ where feasible.
  • Block external access to SharePoint Central Administration.
  • Restrict farm and database communications to required systems.
  • Hunt for and remediate intrusion artifacts, including machine-key harvesters.
  • Review Microsoft’s Improved ASP.NET view state security and key management for best practices.

CISA has added CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 to its Known Exploited Vulnerabilities (KEV) Catalog. Organizations should report any incidents or anomalous activity to CISA via CISA’s 24/7 Operations Center at [email protected] or 1-844-Say-CISA (1-844-729-2472).

Read the full article at CISA Advisories