CISA Just Flagged Active Attacks on SharePoint. Is Your Server Next?

If your organization runs Microsoft SharePoint Server on-premises, this is not a bulletin to skim and forget. On July 14, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent alert confirming active, real-world exploitation of multiple SharePoint vulnerabilities — and updated it again on July 16 to add a fourth flaw to its Known Exploited Vulnerabilities (KEV) Catalog.

Attackers are not waiting for you to patch. They are already inside some environments.

What’s actually happening

CISA confirmed active exploitation of four vulnerabilities — CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644 — affecting every supported on-premises version of SharePoint Server: Subscription Edition, 2019, and 2016.

The attack pattern is methodical, not opportunistic. Threat actors are chaining these flaws to gain remote code execution, then moving into post-exploitation activity: stealing Internet Information Services (IIS) machine keys and using deserialization techniques to establish long-term persistence before deploying malware. That combination matters. It means a successful breach doesn’t end when the initial hole gets patched — attackers who already harvested machine keys can maintain access even after the update is applied, unless those keys are found and rotated.

CISA’s guidance is direct: patch immediately, block external access to SharePoint Central Administration, restrict farm and database communications to only the systems that require them, and review Microsoft’s hardening guidance for ports, services, and configuration settings. Federal agencies were given three days to remediate the most recent addition to the KEV catalog — a signal of how seriously CISA is treating this.

Why this should be on your radar, not just your IT team’s

For mid-market and healthcare organizations, SharePoint isn’t a side system — it’s often where contracts, patient records, financial documents, and internal communications live. A compromised SharePoint farm is a direct line to the data regulators, clients, and boards care about most.

Three things make this alert different from routine patch-cycle noise:

Persistence beats patching. Because attackers can steal IIS machine keys before you patch, applying the update alone may not remove them from your environment. Without hunting for intrusion artifacts and rotating those keys, a “patched” server can still be compromised.

Zero-authentication risk. Some of the flaws involved can be exploited without valid credentials, which removes one of the most basic assumptions IT teams rely on: that internal systems are protected by login walls.

Regulatory exposure. For healthcare organizations bound by HIPAA, or any mid-market business managing regulated or contractual data through SharePoint, a breach here isn’t just an IT incident — it’s a compliance event with reporting obligations and client-trust consequences attached.

What to do this week

Patching is necessary. It is not sufficient on its own.

Where DataGuard365 fits in

This is exactly the scenario our Guardian Absolute Program is built for: technology, methodology, and best practices working together so a vulnerability disclosure like this doesn’t turn into a headline. Our Managed Detection and Response (MDR) team can hunt for signs of compromise in your environment right now, our 24/7 Security Operations Center watches for anomalous activity around the clock, and our Regulatory Compliance Services help healthcare and mid-market organizations navigate what a potential incident means for HIPAA and client obligations.

The industry takes hours to detect a breach. We take minutes.

Get a Free Security Consultation and let us check whether your SharePoint environment shows any signs of compromise — before it becomes a story you have to tell your clients.

Back to Articles/Blog  
Photo of Chris Zvirbulis, Chief Commercial Officer
Christopher Zvirbulis
Chief Commercial Officer, Partner