CISA and Microsoft warned that multiple on-premises SharePoint Server vulnerabilities are being actively exploited against internet-facing systems, with attackers using a chain involving CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 to gain unauthorized access, execute code, steal IIS and ASP.NET machine keys, maintain persistence, and deploy malware. The agencies said the activity affects supported on-premises SharePoint deployments rather than SharePoint Online, and follows earlier Microsoft reporting that Chinese threat actors including Linen Typhoon, Violet Typhoon, and Storm-2603 had abused similar SharePoint flaws to install web shells, dump credentials, move laterally, and in some cases deploy Warlock ransomware.
Microsoft’s July 2026 updates also fixed two additional critical SharePoint bugs, CVE-2026-55040 and CVE-2026-58644, which were not yet confirmed as exploited but were assessed as likely targets for rapid weaponization, while separate reporting said another SharePoint exploit chain may remain unpatched pending a later release. Defenders were urged to immediately apply available patches, enable AMSI in Full Mode, reduce or remove internet exposure, restrict access to SharePoint Central Administration, review logs and endpoint telemetry for compromise, and only rotate IIS or ASP.NET machine keys after confirming whether intrusion activity is already present.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued Alert AL26-017 warning that CVE-2026-56164, CVE-2026-55040, and CVE-2026-58644 affect on-premises Microsoft SharePoint Server. The alert urged organizations to patch, monitor for compromise, and reduce internet exposure, while noting active exploitation of CVE-2026-56164 and related SharePoint flaws.
CISA warned that CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 were under active exploitation against internet-exposed on-premises SharePoint servers. The agency said attackers were stealing IIS machine keys and using deserialization for persistence and malware deployment, while urging hardening and patching.
Microsoft disclosed CVE-2026-55040 and CVE-2026-58644 in on-premises SharePoint Server and issued July 2026 Patch Tuesday updates for SharePoint Server 2016, 2019, and Subscription Edition. Beazley noted Rapid7 had reported a separate SharePoint exploit chain remained unpatched pending an expected August release.
Microsoft said multiple on-premises SharePoint Server vulnerabilities were being actively exploited and attributed observed activity to Linen Typhoon, Violet Typhoon, and Storm-2603. The company described post-exploitation behavior including web shell deployment, ASP.NET MachineKey theft, credential dumping, lateral movement, and Warlock ransomware distribution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcetruesec.com
Open sourcecyberveille.ch
Open sourceresecurity.com
Open sourcetheregister.com
Open sourcelabs.beazley.security
Open sourcemicrosoft.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.