As cited
Copy frozen at (site build).
vulnerabilities
CISA Urges SharePoint Hardening After New Exploitations
CISA has confirmed active exploitation of three SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) affecting all supported on-premises versions, with attackers achieving remote code execution and stealing credentials for persistence. The agency identified two additional unpatched vulnerabilities posing risk and published detection signatures for AMSI and Microsoft Defender. CISA recommends immediate patching, enabling AMSI scanning in Full Mode, hardening network exposure, implementing enhanced logging, and hunting for existing compromise artifacts.
Why it matters: Organizations running on-premises SharePoint Server 2016, 2019, or Subscription Edition face active attacks targeting RCE and credential theft; apply patches immediately and verify AMSI configuration to detect ongoing exploitation before attackers establish durable persistence.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
CISA Urges SharePoint Hardening After New Exploitations
CISA has confirmed active exploitation of three SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) affecting all supported on-premises versions, with attackers achieving remote code execution and stealing credentials for persistence. The agency identified two additional unpatched vulnerabilities posing risk and published detection signatures for AMSI and Microsoft Defender. CISA recommends immediate patching, enabling AMSI scanning in Full Mode, hardening network exposure, implementing enhanced logging, and hunting for existing compromise artifacts.
Why it matters: Organizations running on-premises SharePoint Server 2016, 2019, or Subscription Edition face active attacks targeting RCE and credential theft; apply patches immediately and verify AMSI configuration to detect ongoing exploitation before attackers establish durable persistence.
- Source published
- First seen by Cybersecurity Tracker