Latest CISA Warning: SharePoint Systems at Risk!

July 14, 2026

CISA URGES SHAREPOINT HARDENING AFTER NEW EXPLOITATIONS!

If you business or organization utilizes Microsoft’s SharePoint systems, on premise, then you need to immediately ensure they are secured.  CISA has issued an alert warning on active exploitation of these systems by attackers using CVE-2026-32201, CVE-2026-45659 and CVE-2026-56164.  This allows the attackers to gain unauthorized access to on-premises SharePoint server instances. 

The attacks involved remote code execution and a variety of post-exploitation activities, such as stealing Internet Information Services machine keys and performing deserialization techniques, which provides persistence and the deployment of malware. 

In addition to these ongoing attacks, Microsoft has warned of two more CVE’s which could pose a risk if not patched quickly, they are CVE-2026-55040 and CVE-2026-58644.

If you have SharePoint on premise servers, then follow the recommendations provided by CISA and Microsoft as given below:

  • Apply the latest patches and security updates from Microsoft, verify that installation completes successfully, and shorten patching cycles when possible.
  • Verify that Antimalware Scan Interface (AMSI) integration is enabled for each SharePoint web application. Follow Microsoft’s Configure AMSI integration with SharePoint Server guidance to ensure proper configuration and select the “Full Mode” option for the Request Body Scan Mode, where feasible. When compromise is expected, use the following AMSI and Microsoft Defender Antivirus (MDAV) detections, and implement your organization’s incident response plan for any positive detections:
    • AMSI: Exploit:Script/SuspSignoutReqBody.A – request body scanning; SharePoint Server Subscription only; Microsoft has blocked observed attempts.
    • AMSI: Exploit:Script/ToolPaneAuthBypass.A – request header scanning; SharePoint Server 2016, 2019, and Subscription Edition.
    • AMSI: Exploit:Script/ToolPaneAuthBypass.C – RCE coverage; SharePoint Server 2016, 2019, and Subscription Edition.
    • MDAV: Backdoor:MSIL/LeakFang.A!dha – post-exploitation activity alert involving IIS-protected secrets.

In addition, CISA recommends that organizations implement the following SharePoint Server hardening measures:

  • Before rotating IIS machine keys, hunt for and remediate any intrusion artifacts, including machine-key harvesters, that could allow for the keys to be stolen again. Review Microsoft’s Improved ASP.NET view state security and key management for best practices.
  • Establish tailored logging mechanisms to detect and monitor exploitation activities. Review telemetry for anomalous requests, suspicious SharePoint worker-process activity, webshells, and machine-key access. For more information, see CISA’s Best Practices for Event Logging and Threat Detection.
  • Avoid exposing SharePoint Servers directly to the internet unless necessary; and if necessary, only configure a SharePoint Server behind a Layer 7 reverse proxy or equivalent application-layer security control that requires authentication and can inspect and filter requests. 
  • Block external access to SharePoint Central Administration, restrict farm and database communications to required systems, and review Microsoft’s SharePoint Server security-hardening guidance for role-specific ports, services, and Web.config settings.

References:  https://www.cisa.gov/news-events/alerts/2025/07/20/update-microsoft-releases-guidance-exploitation-sharepoint-vulnerabilities

https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations

Leave a Reply

Discover more from Dave Does Cyber Security

Subscribe now to keep reading and get access to the full archive.

Continue reading