CISA Urges Immediate SharePoint Hardening Following Active Exploitation of Zero-Day Vulnerabilities

WASHINGTON, D.C.: The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive compelling organizations to immediately harden their on-premises Microsoft SharePoint Servers following confirmed, active exploitation of multiple critical vulnerabilities, including a severe zero-day flaw.
Updated on July 16, 2026, the federal advisory highlights that cyber threat actors are actively leveraging vulnerabilities CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and the newly cataloged CVE-2026-58644 to gain unauthorized access to enterprise environments. These flaws affect all supported on-premises SharePoint Server versions, including Subscription Edition, 2019, and 2016, enabling attackers to execute remote code execution (RCE) and conduct sophisticated post-exploitation activities.
The Anatomy of the Exploit
According to CISA’s technical analysis, the exploitation chain typically begins with an unauthenticated attacker sending a specially crafted request to a vulnerable SharePoint instance. Upon successful exploitation, threat actors harvest Internet Information Services (IIS) machine keys. This chokepoint in the security architecture allows adversaries to forge authentication tokens, establish persistent backdoor access, and deploy advanced malware deep within the corporate network.
"Organizations must not treat this as a routine patching cycle. The active exploitation of these vulnerabilities represents a severe and exigent threat to enterprise infrastructure. Immediate remediation and proactive threat hunting are non-negotiable," stated a senior CISA threat intelligence analyst.
Mandatory Mitigation and Hardening Protocols
To counter this pervasive threat, CISA has outlined a stringent set of defensive measures. Foremost among these is the immediate application of Microsoft’s latest security updates, coupled with the verification of successful installation. Furthermore, administrators are urged to enable Antimalware Scan Interface (AMSI) integration for each SharePoint web application, specifically selecting the "Full Mode" option for Request Body Scan Mode to intercept malicious payloads.
CISA also emphasizes the critical importance of network segmentation. Organizations are strongly advised to avoid exposing SharePoint Servers directly to the public internet. If external access is absolutely necessary, it must be routed exclusively through a Layer 7 reverse proxy or an equivalent application-layer security control capable of deep packet inspection and robust authentication enforcement.
Note: An official social media embed from the primary agency for this specific technical alert is currently being archived. For verified official statements, complete technical indicators of compromise (IOCs), and the full remediation guide, please refer to the CISA official alert page or the The Hacker News official coverage.
As the threat landscape continues to evolve with alarming velocity, this directive serves as a stark reminder that foundational network hygiene and rapid vulnerability management remain the most effective bulwarks against sophisticated, state-sponsored, and financially motivated cyber campaigns.




Comments (0)
No comments yet. Be the first to share your thoughts!
Want to join the discussion?
Please log in to post a comment.
Login NoworCreate an Account