← All stories
● Covered by 5 sources · 27 reportsHigh impact8 negative6 neutral

CISA Alerts on Active Exploitation of Multiple Microsoft SharePoint Vulnerabilities

🔄 Updated 23d ago — new reporting from BleepingComputer, The Record, SecurityWeek, The Hacker News, ZDNET
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • CISA added four SharePoint vulnerabilities to its KEV catalog.
  • CVE-2026-45659, CVE-2026-58644, and CVE-2026-50522 allow remote code execution.
  • CVE-2026-56164 is a privilege escalation flaw.
  • Exploitation often requires minimal privileges or no authentication.
  • Federal agencies must patch these flaws by CISA-mandated deadlines.
  • CVE-2026-45659 has a CVSS score of 8.8.
  • CVE-2026-45659 was addressed by Microsoft in May 2026.
  • CVE-2026-45659 impacts SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016.
  • CVE-2026-45659 is a deserialization of untrusted data vulnerability.
  • CVE-2026-45659 requires Site Member permissions for exploitation.
  • CISA mandated federal agencies patch CVE-2026-45659 by July 4, 2026.
  • Microsoft patched a record 622 vulnerabilities.
  • CVE-2026-56164 affects on-premises SharePoint Server.
  • CVE-2026-56164 was credited to Mandiant's incident responders and Google's FLARE team.
  • CISA warned of three actively exploited SharePoint vulnerabilities: CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164.
  • CVE-2026-32201 is a spoofing issue patched in April.
  • CVE-2026-55040 is a critical security bypass weakness.
  • CVE-2026-58644 has a CVSS score of 9.8.
  • CVE-2026-58644 allows an attacker authenticated as a Site Owner to execute code.
  • CISA mandated federal agencies patch CVE-2026-58644 by July 19, 2026.
  • CVE-2026-50522 has a CVSS score of 9.8.
  • CVE-2026-50522 was discovered by DEVCORE researcher "splitline".
  • CVE-2026-50522 allows an attacker authenticated as a Site Owner to execute code.
  • CVE-2026-50522 is being exploited to steal machine keys.
  • Defused observed exploitation attempts targeting CVE-2026-50522 on July 17.

Overview of Exploited Vulnerabilities

CISA has issued a warning about multiple actively exploited vulnerabilities in Microsoft SharePoint Server. These include CVE-2026-45659, CVE-2026-50522, and CVE-2026-58644, all involving the deserialization of untrusted data. Exploitation allows attackers to run arbitrary code remotely, posing significant security risks to affected systems.

Details of Key Vulnerabilities

CVE-2026-45659 allows an authenticated attacker with site member permissions to execute arbitrary code on impacted SharePoint servers. Initially assessed as 'Exploitation Less Likely' by Microsoft, it was marked by CISA due to increased exploitation.

In addition, CVE-2026-50522, with a CVSS score of 9.8, emerged following the release of proof-of-concept exploit code targeting SharePoint's deserialization flaw, leading to unauthorized access and potential data compromise.

Microsoft's Security Updates

Microsoft issued patches in its July 2026 security updates to address these vulnerabilities. These updates aim to reduce exploitation risks by correcting the underlying flaws across multiple SharePoint versions, including Subscription Edition and Server 2019.

Urgent Patch Mandates

CISA has mandated federal agencies patch these vulnerabilities under its Known Exploited Vulnerabilities (KEV) guidelines by specific deadlines. Prompt patching is crucial to mitigate potential damage from these security breaches.

Impact on Organizations

Organizations using Microsoft SharePoint are advised to implement the provided patches immediately. Failure to do so may result in unauthorized access and persistent threats, notably from attackers leveraging these exploits to breach critical systems.

Updates

🕒 2026-07-24 · new reporting from The Hacker News
  • CVE-2026-45659 has a CVSS score of 8.8.
  • CVE-2026-45659 was addressed by Microsoft in May 2026.
  • CVE-2026-45659 impacts SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016.
  • CVE-2026-45659 is a deserialization of untrusted data vulnerability.
  • CVE-2026-45659 requires Site Member permissions for exploitation.
  • CISA mandated federal agencies patch CVE-2026-45659 by July 4, 2026.
  • Microsoft patched a record 622 vulnerabilities.
  • CVE-2026-56164 is a privilege escalation flaw.
  • CVE-2026-56164 affects on-premises SharePoint Server.
  • CVE-2026-56164 was credited to Mandiant's incident responders and Google's FLARE team.
  • CISA warned of three actively exploited SharePoint vulnerabilities: CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164.
  • CVE-2026-32201 is a spoofing issue patched in April.
  • CVE-2026-55040 is a critical security bypass weakness.
  • CVE-2026-58644 has a CVSS score of 9.8.
  • CVE-2026-58644 allows an attacker authenticated as a Site Owner to execute code.
  • CISA mandated federal agencies patch CVE-2026-58644 by July 19, 2026.
  • CVE-2026-50522 has a CVSS score of 9.8.
  • CVE-2026-50522 was discovered by DEVCORE researcher "splitline".
  • CVE-2026-50522 allows an attacker authenticated as a Site Owner to execute code.
  • CVE-2026-50522 is being exploited to steal machine keys.
  • Defused observed exploitation attempts targeting CVE-2026-50522 on July 17.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~11 min · 9 stories · Aug 16

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Threat actors are exploiting CVE-2026-55040, a critical authentication bypass vulnerability in Microsoft SharePoint, following the public release of a proof-of-concept (PoC) exploit. This vulnerability allows unauthenticated attackers to impersonate users or administrators and access or modify data on vulnerable SharePoint servers.

A SharePoint vulnerability, CVE-2026-55040, patched by Microsoft in July, is now being actively exploited in the wild, with attacks emerging shortly after a public proof-of-concept (PoC) exploit was released. This exploitation allows unauthenticated attackers to bypass security features, potentially leading to file disclosure and data modification in SharePoint instances.

Microsoft's August Patch Tuesday update addresses 421 vulnerabilities across its products, including a Windows zero-day flaw that has been actively exploited. This update is critical for Windows users as the exploited vulnerability allows attackers to gain system privileges without user interaction after an initial intrusion.

A critical authentication bypass vulnerability in Microsoft SharePoint, CVE-2026-55040, is being exploited in attacks after a proof-of-concept (PoC) exploit was published by Rapid7. This flaw allows unprivileged attackers to impersonate SharePoint users or administrators, potentially leading to file disclosure and data modification.

Microsoft released its monthly security updates, addressing 398 vulnerabilities, including a Windows kernel driver flaw (CVE-2026-68820) that is actively being exploited for privilege escalation. The update also includes patches for four critical remote code execution flaws with CVSS scores of 9.8 that do not require user interaction. This update is significant as it addresses an actively exploited vulnerability and numerous other critical issues, requiring immediate attention from system administrators.

Microsoft released patches for 421 vulnerabilities in its August 2026 Patch Tuesday update, including a high-severity zero-day vulnerability (CVE-2026-68820) in the Ancillary Function Driver for WinSock that is actively being exploited. This update is critical for Windows users as it addresses privilege escalation flaws, some of which are publicly disclosed and likely to be exploited.

Security researchers, using AI assistance, discovered a critical exploit chain in Microsoft SharePoint servers (CVE-2026-55040 and CVE-2026-63520) that allows unauthenticated remote code execution. This vulnerability affects SharePoint Server Subscription Edition, 2019, and 2016, enabling attackers to assume any user's identity, including administrators, and run code on the server.

The Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware groups are actively exploiting a high-severity Microsoft SharePoint remote code execution vulnerability, CVE-2026-45659. This flaw allows low-privileged attackers to execute arbitrary code on unpatched SharePoint servers, posing a significant risk to organizations using the software.

Microsoft patched over a dozen vulnerabilities across its products, including critical remote code execution and elevation of privilege issues. Apple released an update for a single bug that could bypass Screen Sharing authentication. These updates address security flaws that could be exploited over networks, impacting user security across various platforms.

The Swiss Federal Office for Information Technology and Telecommunication (BIT) reported a breach of its Microsoft SharePoint servers, compromising approximately 200 accounts. This incident highlights the ongoing risk posed by unpatched vulnerabilities, as the attackers likely exploited flaws disclosed and fixed by Microsoft in mid-July.

Switzerland's Federal Office for Information Technology and Communications (BIT) disclosed that hackers compromised approximately 200 accounts on its on-premises SharePoint servers. The agency suspects the attack exploited vulnerabilities identified in July's Patch Tuesday, which are also listed in CISA's Known Exploited Vulnerabilities catalog. This incident highlights the ongoing risk associated with SharePoint vulnerabilities, particularly for organizations exposing the service directly to the internet.

A proof-of-concept exploit for "Certighost" (CVE-2026-54121), a vulnerability in Windows Active Directory Certificate Services, has been publicly released. This exploit allows authenticated attackers to potentially compromise a Windows domain by impersonating a Domain Controller and performing privileged Active Directory operations.

Security researchers published a working exploit, dubbed Certighost, that allows a low-privileged Active Directory user to obtain a certificate for a Domain Controller and authenticate as that machine. This exploit leverages a flaw in Active Directory Certificate Services (AD CS) that Microsoft patched as CVE-2026-54121, enabling attackers to potentially retrieve the krbtgt secret through DCSync.

Check Point released security updates for its Security Management and Multi-Domain Management products, addressing multiple vulnerabilities including one actively exploited in the wild. The critical flaw, CVE-2026-16232, allowed unauthenticated remote attackers to gain full administrative privileges on SmartConsole. This impacts customers with management servers exposed directly to the internet without IP restrictions, enabling attackers to modify security policies and configurations.

Another SharePoint vulnerability, CVE-2026-50522, has been exploited in the wild, marking the fourth such case in a month. This critical flaw allows remote code execution and has been confirmed by multiple security firms as a significant risk to affected organizations.

Hackers are exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys, enabling long-term unauthorized access to affected servers. Microsoft had previously issued patches for this deserialization flaw, but with the public release of proof-of-concept exploit code, attackers began targeting vulnerable installations immediately.

CVE-2026-50522 in Microsoft SharePoint Server, with a CVSS score of 9.8, is actively being exploited following the release of a public proof-of-concept exploit. This vulnerability allows an attacker with Site Owner credentials to execute arbitrary code remotely, posing significant risks to on-premises SharePoint deployments.

CISA reports ongoing exploitation of the critical RCE vulnerability CVE-2026-58644 in Microsoft SharePoint. This flaw has a CVSS score of 9.8 and allows attackers to execute arbitrary code, prompting urgent patching recommendations for federal agencies.

CISA has included CVE-2026-58644, a critical zero-day vulnerability in Microsoft SharePoint, in its Known Exploited Vulnerabilities catalog. Agencies must implement fixes by July 19, 2026, following reports of active exploitation.

CISA has directed federal agencies to patch a critical vulnerability in Oracle E-Business Suite by July 18 due to ongoing exploitation. The vulnerability allows unauthenticated attackers to gain control of systems, highlighting significant risks in federal cybersecurity.

CISA has urged immediate patching of multiple zero-day vulnerabilities in Microsoft SharePoint, including newly disclosed CVE-2026-56164. These critical vulnerabilities pose serious risks for organizations if not addressed promptly, particularly in potential remote code execution scenarios.

CISA has issued a warning regarding three actively exploited vulnerabilities in on-premises SharePoint Server instances. This is significant as exploited vulnerabilities could allow attackers to execute remote code, steal sensitive keys, and deploy malware on affected systems.

Microsoft released its largest Patch Tuesday ever, addressing 622 vulnerabilities, including two zero-days being actively exploited in the wild. The critical patches for SharePoint Server and Active Directory Federation Services are essential due to their potential for privilege escalation attacks.

Microsoft released patches for 622 vulnerabilities, including two zero-days in Active Directory and SharePoint Server. The fixes address critical security flaws, significantly enhancing protection for users and organizations against potential exploits.

CISA has confirmed that a high-severity remote code execution vulnerability in Microsoft SharePoint, tracked as CVE-2026-45659, is being actively exploited. This flaw allows low-privileged authenticated attackers to execute arbitrary code on vulnerable servers, posing significant risks especially for federal agencies that must secure their systems by a mandated deadline.

CISA has identified a high-severity vulnerability (CVE-2026-45659) in Microsoft SharePoint Server being actively exploited by threat actors. This flaw allows attackers with site member permissions to execute arbitrary code, emphasizing the need for urgent patching by organizations.

CISA added CVE-2026-45659, a high-severity remote code execution vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog due to active exploitation. This flaw allows authenticated attackers to execute code without elevated privileges, impacting network security for federal agencies required to apply patches by July 4, 2026.