news.mlab.sh
Back to the feed
vulnerability

CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities

High
Summary

The CISA is urging immediate patching of Microsoft SharePoint servers due to several recently disclosed zero-day vulnerabilities. These flaws could allow remote code execution and enable attackers to steal sensitive information. The agency has added CVE-2026-56164 to its KEV list, requiring federal agencies to address the issue within three days.

The US Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday urged immediate hardening of Microsoft SharePoint servers in light of several recently disclosed zero-day vulnerabilities. The agency has added CVE-2026-56164 to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to address the issue within three days.

Microsoft’s latest round of security updates resolved CVE-2026-55040 and CVE-2026-58644, critical-severity SharePoint bugs that could be exploited remotely to bypass a security feature and to execute arbitrary code. These vulnerabilities, along with CVE-2026-32201, a spoofing issue, have been exploited as zero-days.

“These vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution (RCE) and post-exploitation activities, such as stealing Internet Information Services (IIS) machine keys and performing deserialization techniques, to gain persistence and deploy malware,” CISA warns.

To mitigate these risks, CISA recommends that organizations monitor their SharePoint servers to identify any signs of unusual activity, which could point to active exploitation. In addition to applying Microsoft’s patches, organizations are advised to ensure that their security products cover all SharePoint web applications, hunt for intrusions, rotate IIS machine keys, enable tailored logging, ensure that SharePoint servers are not directly exposed to the internet, and restrict access to the administration interfaces.

Read the full article at SecurityWeek