CISA Urges SharePoint Hardening After New Exploitations
p CISA is aware of active exploitation of vulnerabilities a href= https://www.cve.org/CVERecord?id=CVE-2026-32201 target= _blank CVE-2026-32201 /a , a href= https://www.cve.org/CVERecord?id=CVE-2026-45659 target= _blank CVE-2026-45659 /a , and a href= https://www.cve.org/CVERecord?id=CVE-2026-56164 target= _blank CVE-2026-56164 /a , enabling cyber threat actors to gain unauthorized access to on-premises SharePoint Server instances. These vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution (RCE) and post-exploitation activities, such as stealing Internet Information Services (IIS) machine keys and performing deserialization techniques, to gain persistence and deploy malware. Organizations should monitor affected SharePoint Servers closely for any signs of exploitation or unusual activity. nbsp; /p p Additionally, the following newly disclosed CVEs are not yet known to have been exploited, but Microsoft has identified them as posing a potential risk if left unpatched: /p ul type= square li a href= https://www.cve.org/CVERecord?id=CVE-2026-55040 target= _blank CVE-2026-55040 /a /li li a href= https://www.cve.org/CVERecord?id=CVE-2026-58644 target= _blank CVE-2026-58644 /a /li /ul p CISA urges organizations to detect and remediate a potential compromise by implementing the following recommendations: /p ul type= square li Apply the latest patches and security updates from Microsoft, verify that installation completes successfully, and shorten patching cycles when possible. /li li Verify that Antimalware Scan Interface (AMSI) integration is enabled for each SharePoint web application. Follow Microsoft’s a href= https://learn.microsoft.com/en-us/sharepoint/security-for-sharepoint-server/configure-amsi-integration target= _blank Configure AMSI integration with SharePoint Server /a guidance to ensure proper configuration and select the “Full Mode” option for the Request Body Scan Mode, where feasible. When compromise is expected, use the following AMSI and Microsoft Defender Antivirus (MDAV) detections, and implement your organization’s incident response plan for any positive detections: br ul type= circle li AMSI: code Exploit:Script/SuspSignoutReqBody.A /code – request body scanning; SharePoint Server Subscription only; Microsoft has blocked observed attempts. /li li AMSI: code Exploit:Script/ToolPaneAuthBypass.A /code – request header scanning; SharePoint Server 2016, 2019, and Subscription Edition. /li li AMSI: code Exploit:Script/ToolPaneAuthBypass.C /code – RCE coverage; SharePoint Server 2016, 2019, and Subscription Edition. /li li MDAV: code Backdoor:MSIL/LeakFang.A!dha /code – post-exploitation activity alert involving IIS-protected secrets. /li /ul /li /ul p In addition, CISA recommends that organizations implement the following SharePoint Server hardening measures: /p ul type= square li Before rotating IIS machine keys, hunt for and rem
Sign in to read the full article
Create a free account to access all news, downloads, and community features
Originally published by CISA
This article is shared for informational purposes. All rights belong to the original author and publisher. If you are the copyright holder and would like this content removed, please contact us.