CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2710

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities

CISA confirmed active exploitation of three Microsoft SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) affecting on-premises deployments across all supported versions. Two additional high-severity flaws (CVE-2026-55040 and CVE-2026-58644) were disclosed July 14-15, 2026, with CVE-2026-58644 confirmed exploited in the wild. Attackers chain these flaws to gain unauthorized access, achieve remote code execution, steal IIS machine keys, and deploy malware for persistence.

Why it matters: Organizations running on-premises SharePoint Server 2016, 2019, or Subscription Edition face immediate risk from active attacks; patching all five vulnerabilities and applying Microsoft Defender signatures is critical to prevent remote compromise and lateral movement.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities

Cybersecurity and Infrastructure Security Agency (CISA) confirmed active exploitation of four Microsoft SharePoint Server vulnerabilities, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644, which attackers chain together to compromise on-premises deployments. The flaws enable spoofing, remote code execution (RCE), and privilege escalation, with attackers using them to steal IIS machine keys and establish persistence. Microsoft has released patches for all five vulnerabilities in the alert, with detection signatures available for three of them.

Why it matters: Organizations operating SharePoint Server on-premises (versions 2016, 2019, and Subscription Edition) must patch immediately to block active in-the-wild attacks exploiting these critical flaws for unauthorized access and malware deployment.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities

Cybersecurity and Infrastructure Security Agency (CISA) confirmed active exploitation of four Microsoft SharePoint Server vulnerabilities, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644, which attackers chain together to compromise on-premises deployments. The flaws enable spoofing, remote code execution (RCE), and privilege escalation, with attackers using them to steal IIS machine keys and establish persistence. Microsoft has released patches for all five vulnerabilities in the alert, with detection signatures available for three of them.

Why it matters: Organizations operating SharePoint Server on-premises (versions 2016, 2019, and Subscription Edition) must patch immediately to block active in-the-wild attacks exploiting these critical flaws for unauthorized access and malware deployment.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary