XOOMAR
Enterprise servers under cyberattack protected by glowing shields and urgent patching visuals.
CybersecurityJuly 15, 2026· 5 min read· By XOOMAR Insights Team

Exploited SharePoint Vulnerabilities Trigger 3-Day Race

Share
Updated on July 15, 2026

On Tuesday, CISA urged organizations to harden on-premises Microsoft SharePoint Server systems after confirming active exploitation of three SharePoint Server flaws, including flaws that were targeted before fixes were available.

XOOMAR Intelligence

Analyst Take

70/ 100
High
4 sources analyzedLow confidenceTrend20Freshness93Source Trust85Factual Grounding94Signal Cluster40

The warning follows Microsoft’s July 2026 Patch Tuesday updates and puts federal agencies on a fast clock for at least one newly cataloged bug, according to SecurityWeek. The newest exploited flaw, CVE-2026-56164, is a privilege escalation issue that can be exploited remotely without authentication.

July 14: CISA adds CVE-2026-56164 to the KEV catalog

CISA added CVE-2026-56164 to its Known Exploited Vulnerabilities catalog on Tuesday and urged federal agencies to patch it within three days, in line with BOD 26-04 recommendations.

That deadline applies specifically to CVE-2026-56164. Other SharePoint flaws were added to the KEV catalog earlier: CVE-2026-32201 on April 14, 2026, and CVE-2026-45659 on July 1, 2026, according to CISA’s July 14 alert.

“These vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution (RCE) and post-exploitation activities, such as stealing Internet Information Services (IIS) machine keys and performing deserialization techniques, to gain persistence and deploy malware,” CISA warned.

CISA said attackers are actively exploiting CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 to gain unauthorized access to on-premises SharePoint Server instances.

The agency also flagged two newly disclosed SharePoint bugs, CVE-2026-55040 and CVE-2026-58644. Those are not currently listed by CISA as exploited, but Microsoft identified them as risks if left unpatched.

CVE CISA status Source-described impact
CVE-2026-56164 Actively exploited, added to KEV on July 14, 2026 Privilege escalation, remotely exploitable without authentication
CVE-2026-32201 Actively exploited, added to KEV on April 14, 2026 Spoofing issue, patched in April after zero-day exploitation
CVE-2026-45659 Actively exploited, added to KEV on July 1, 2026 Code execution issue, patched in May via out-of-band update
CVE-2026-55040 Not flagged as exploited Critical-severity bug that can bypass a security feature
CVE-2026-58644 Not flagged as exploited Critical-severity bug that can execute arbitrary code

April to July: SharePoint zero-days turn into a hardening emergency

The SharePoint vulnerabilities now sit across several patch cycles. CVE-2026-32201 was patched in April after being exploited as a zero-day. CVE-2026-45659 was patched in May through an out-of-band security update. CVE-2026-56164 was resolved in Microsoft’s July 2026 Patch Tuesday release.

That sequencing matters. CISA is not only telling administrators to install the latest patches. It is telling them to assume some servers may already have been touched.

The risk CISA describes is not theoretical access followed by vague damage. The agency points to remote code execution, theft of IIS machine keys, deserialization activity used for persistence, and malware deployment. Those are post-compromise signals, not simple scanning noise.

For defenders, the sharp edge is exposure. CISA specifically recommends that organizations avoid putting SharePoint Servers directly on the internet unless necessary. If internet exposure is required, CISA says servers should sit behind a Layer 7 reverse proxy or similar application-layer control that requires authentication and can inspect and filter requests.

That advice narrows the immediate priority list:

  • Patch status: Apply Microsoft’s latest SharePoint security updates and verify installation completed successfully.
  • Exposure: Identify on-premises SharePoint servers reachable from the internet.
  • Access control: Block external access to SharePoint Central Administration.
  • Persistence checks: Hunt for intrusion artifacts before rotating IIS machine keys.
  • Logging: Review telemetry for anomalous requests, suspicious SharePoint worker-process activity, webshells, and machine-key access.

For readers tracking adjacent intrusion tradecraft, XOOMAR has covered separate security stories including Ghost Accounts Forge Attack Maps With GitHub API Abuse and GhostExodus Forces Cybersecurity to Trust a Rule-Breaker. Those reports are not attributed to this SharePoint activity, but they sit in the same practical bucket for defenders: know what your systems expose, and verify what happened after access was gained.

Security teams now have two jobs: patch and prove nothing landed

CISA’s guidance pushes organizations beyond routine patch management. The agency recommends monitoring affected SharePoint servers for unusual activity and implementing incident response plans when detections fire.

The alert names specific Microsoft protections and detections, including AMSI coverage for SharePoint web applications and Microsoft Defender Antivirus detection Backdoor:MSIL/LeakFang.A!dha, tied to post-exploitation activity involving IIS-protected secrets.

Administrators should not rotate IIS machine keys blindly. CISA says organizations should first hunt for and remediate intrusion artifacts, including machine-key harvesters, so newly rotated keys are not stolen again.

That is the practical lesson in this alert. Patching closes known doors. It does not erase evidence of attackers who may have entered before the fix landed.

Private-sector organizations are not bound by the federal KEV deadlines in the same way agencies are, but CISA’s timeline is a clear severity signal. A three-day remediation window for CVE-2026-56164 leaves little room for slow maintenance cycles.

The next decision point is whether exploitation expands around the two newly disclosed bugs that CISA says are not yet known to be exploited: CVE-2026-55040 and CVE-2026-58644. If either moves into the KEV catalog, administrators who treated July’s SharePoint updates as optional will be behind again.

CISA says it may update the alert as new guidance emerges. Until then, the priority is narrow and urgent: patch on-premises SharePoint Server, reduce direct internet exposure, hunt for compromise, and treat clean installation logs as only the start of the response.

Impact Analysis

  • CISA says attackers are already exploiting SharePoint flaws to gain unauthorized access.
  • Federal agencies face a three-day patch deadline for CVE-2026-56164.
  • Organizations running on-premises SharePoint Server 2016, 2019, or Subscription Edition may be exposed.

SharePoint vulnerabilities cited by CISA

VulnerabilityCISA KEV statusExploitation statusKey detail
CVE-2026-56164Added July 14, 2026Actively exploitedRemote privilege escalation; federal agencies urged to patch within three days
CVE-2026-32201Added April 14, 2026Actively exploitedAffects supported on-premises SharePoint Server versions
CVE-2026-45659Added July 1, 2026Actively exploitedLinked to unauthorized access against on-premises SharePoint Server instances
CVE-2026-55040Not currently listed as exploited by CISANo active exploitation reported by CISANewly disclosed SharePoint bug
CVE-2026-58644Not currently listed as exploited by CISANo active exploitation reported by CISANewly disclosed SharePoint bug
XOOMAR

Written by

XOOMAR Insights Team

Research and Editorial Desk

The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.

Related Articles

Text 'Cyber Attack' on textured dark paper highlights digital security threat concept.Cybersecurity

Hackers Mass-Exploit Patched SharePoint Flaw After Public PoC

Attackers are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040) using public proof-of-concept code, targeting organizations tha

Aug 13, 20265 min
Cyberattack concept over a water treatment plant with locked control systems and digital security visualsCybersecurity

Exposed PLCs Trigger CISA Water Systems Attack Alarm

CISA says exposed PLCs are letting attackers lock out water operators, with Minnesota incidents and boil water notices raising the stakes.

Aug 1, 20266 min
Conceptual image showing the words 'Ethical Hacking' on a textured abstract background.Cybersecurity

Critical Gitea Bug Hijacks Systems for Crypto Mining

A critical Gitea vulnerability is under active attack, letting hackers hijack servers for cryptocurrency mining, confirmed by CISA's urgent patch order.

Aug 26, 20267 min
Chain-locked book, phone, and laptop symbolizing digital and intellectual security.Cybersecurity

Feds Set Deadline as Hackers Hit AI Tool, Web Server Code

The US government has issued a mandatory remediation deadline after confirming attackers are actively exploiting critical bugs in Langflow, Apache Tomcat, and N

Aug 6, 20265 min
Snowy water utility shielded from cyber intrusions with dark code overlays and security locks.Cybersecurity

Iran Shadow Looms Over Minnesota Water Cyberattacks

A leaked memo links 30-plus Minnesota water utility intrusions to Iran-affiliated hackers, raising alarms over civilian infrastructure.

Aug 2, 20268 min
Detailed view of a GeForce RTX graphics card, highlighting modern technology.Technology

Nvidia's $92 Billion Stress Test Crushes AI Investors

Nvidia's Q2 earnings have become a do-or-die test for the AI trade, where even beating a $92 billion revenue target may not satisfy investors now demanding flaw

Aug 29, 20266 min
Colorful lines of code on a computer screen showcasing programming and technology focus.Technology

QueryStory Raises $6M to Fix AI's Broken Truth Problem

QueryStory raised $6 million to build an AI reporting tool that proves where its conclusions come from, aiming to solve enterprise trust issues with data audits

Aug 30, 20269 min
A boy and girl collaborate on a robotics project using a digital screen in a classroom setting.Technology

Art Thief Returns Loot, Builds Artists' Shield

A hacker who stole millions of artworks from an anti-AI portfolio site has apologized and is now collaborating with its founder to build a defensive tool for ar

Aug 28, 20266 min
Visionary leader in an Apple innovation hub at night, gesturing towards holographic product schematics with neural network motifs.Technology

Apple's $4.5T Gambit on a Hardware CEO

Apple's surprise choice of longtime hardware engineer John Ternus as CEO signals a massive bet on product refinement over a radical software or AI pivot, placin

Sep 1, 202610 min
Photorealistic image of a high-tech electric toothbrush with camera, surrounded by digital interfaces and misty jets in a futuristic lab setting.Technology

Dyson Installs Camera In Your Mouth For $499

Dyson’s $499 CameraJet toothbrush uses a real-time camera and pressurized mouthwash jets to replace flossing, marking the brand's most intimate and costly foray

Sep 1, 20266 min

Don't miss the signal

Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.

Free forever. No spam. Unsubscribe anytime.