Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft SharePoint Server actively exploited multi-CVE wave

Exploitation Wave
First reported
Last updated
Happening score
H score 79
3 unique sources, 4 articles

Summary

Hide ▲

SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used to bypass authentication, reach remote code execution, and enable IIS machine key theft, persistence, and malware deployment. CISA added the exploited CVEs to the Known Exploited Vulnerabilities Catalog and urged operators to apply Microsoft's latest patches, verify installation, enable AMSI and Microsoft Defender Antivirus detections, reduce direct internet exposure, block SharePoint Central Administration, and use a Layer 7 reverse proxy where needed.

Cases

Related Happenings

CISA Microsoft SharePoint hardening guidance for exploited zero-days

Advisory/Mitigation
H score56 First: 15.07.2026 17:07 Last: 15.07.2026 17:07 Sources 1

How related: The development comes as CISA warned of active exploitation of multiple SharePoint Server vulnerabilities, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644, that could enable threat actors to gain unauthorized access to on-premises instances.

About this happening: CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...

SharePoint Server unauthenticated privilege escalation flaw actively exploited (CVE-2026-56164)

Vulnerability
H score82 First: 14.07.2026 23:25 Last: 14.07.2026 23:25 Sources 1

How related: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances.

About this happening: CVE-2026-56164 is an actively exploited SharePoint Server vulnerability that lets an unauthenticated attacker escalate privileges over the network. The flaw puts *...

Latest development: 15.07.2026 12:20

Microsoft’s July 14 Patch Tuesday included CVE-2026-56164, an elevation-of-privilege flaw in Microsoft SharePoint Server that required no existing privileges and was described as low complexity. The zero-day was one of two vulnerabilities in the release that had been exploited in the wild, and Microsoft issued updates for affected systems.

Microsoft security patch release for CVE-2026-56164

Security Patch Release
H score11 First: 14.07.2026 23:25 Last: 14.07.2026 23:25 Sources 1

How related: SharePoint Server Flaws in Spotlight

About this happening: Microsoft released a record 622-CVE Patch Tuesday that includes two exploited flaws in SharePoint Server and Active Directory Federation Services, raising urgency...

Microsoft Corp. security patch release for CVE-2026-56155

Security Patch Release
H score56 First: 14.07.2026 22:22 Last: 14.07.2026 22:22 Sources 1

How related: Patches for the flaw have been released as part of the Patch Tuesday updates released on July 14, 2026.

About this happening: Microsoft released July 2026 Patch Tuesday updates that close at least 570 security holes in Windows and other software, expanding the remediation burden for defen...

Microsoft Malware Protection Engine race-condition elevation-of-privilege remote code execution flaw (CVE-2026-50656)

Vulnerability
H score32 First: 17.06.2026 11:32 Last: 17.06.2026 11:32 Sources 1

About this happening: Microsoft has released a security update for CVE-2026-50656 after public disclosure of RoguePlanet, a privilege-escalation flaw in the Microsoft Malware Protecti...

Timeline

  1. 15.07.2026 12:44 1 articles · 13d ago

    Microsoft patches CVE-2026-55040 and CVE-2026-58644

    Mitigation Patch Update

    Microsoft patched CVE-2026-55040 and CVE-2026-58644 on Tuesday after CISA flagged the two SharePoint Server vulnerabilities as attractive targets for attackers, although they were not yet known to have been exploited in the wild.

    Show sources
  2. 15.07.2026 12:44 5 articles · 13d ago

    CISA warns of active SharePoint Server exploitation

    Initial Disclosure

    CISA warned that attackers are actively exploiting CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 against Internet-exposed on-premises SharePoint Server instances, using the flaws to bypass authentication, gain remote code execution, steal IIS machine keys, establish persistence, and deploy malware. CISA also urged affected operators to apply Microsoft's latest patches, verify successful installation, enable AMSI integration and Microsoft Defender Antivirus detections, monitor for intrusion artifacts, avoid direct internet exposure where possible, block external access to SharePoint Central Administration, and place exposed servers behind a Layer 7 reverse proxy when needed.

    Show sources