CISA warns of three actively exploited SharePoint flaws

CISA urges organizations to patch three actively exploited SharePoint vulnerabilities. Protect your servers from ransomware and attacks.

lunes, 27 de julio de 2026 • 4 min read • Q2BSTUDIO Team

Medidas urgentes de seguridad para SharePoint ante ataques

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert for all organizations running Microsoft SharePoint in on-premises deployments. The warning focuses on three vulnerabilities that are already being actively exploited by cybercriminals, affecting all supported versions of SharePoint Server. These flaws represent a critical risk for enterprise security, especially in environments where document management and internal collaboration heavily rely on this platform. In a context where digital transformation is advancing rapidly, cybersecurity becomes a fundamental pillar to protect information assets. Companies like Q2BSTUDIO, specialized in custom software development, recommend a thorough review of security configurations and immediate patch implementation.

The vulnerabilities highlighted by CISA include a spoofing bug (CVE-2026-32201, score 6.5), disclosed by Microsoft in March and confirmed as actively exploited in June. The second is a remote code execution (RCE) vulnerability identified as CVE-2026-45659 (8.8), published in June and confirmed as being used in attacks last week, despite Microsoft initially labeling its exploitation as 'less likely.' The third, CVE-2026-56164 (5.3), is a privilege escalation flaw that was part of the record 622 bugs fixed in the latest Patch Tuesday. Additionally, CISA mentioned two more critical vulnerabilities from the same patch cycle: CVE-2026-55040 (9.1) and CVE-2026-58644 (9.8), although neither has been exploited yet, both have been tagged by Microsoft as 'Exploitation More Likely.'

The impact of these breaches goes beyond unauthorized access. According to CISA's statement, attackers are using these vulnerabilities in post-exploitation activities that include stealing Internet Information Services (IIS) machine keys and deserialization techniques, aiming to gain persistence in compromised systems and deploy malware. Such attacks often precede major incidents like ransomware installation or sensitive data exfiltration. The agency did not specify which actors are behind these attacks, but recalled a previous alert from August 2025 linking SharePoint vulnerabilities to Warlock ransomware, attributed by Microsoft to Chinese state-sponsored groups.

For companies managing critical infrastructures, protecting SharePoint is not optional. The platform is used in numerous business processes, from document management to workflow automation. A breach in this system can compromise the integrity of corporate data, intellectual property, and internal communications. Therefore, cybersecurity experts recommend applying the latest Microsoft security updates, verifying that Antimalware Scan Interface (AMSI) integration is enabled for each SharePoint web application, and rotating IIS keys after conducting proactive threat hunting. Additionally, it is advised to limit public exposure of the SharePoint server and block external access to the Central Administration console.

From an enterprise architecture perspective, many organizations choose to migrate their workloads to the cloud to reduce the attack surface. Cloud services like AWS or Azure offer additional layers of managed security, though shared responsibility remains a key factor. In this regard, Q2BSTUDIO provides cloud services on AWS and Azure that enable companies to design secure and scalable environments, minimizing risks associated with vulnerabilities like those in SharePoint. Furthermore, implementing artificial intelligence (AI) solutions can help detect anomalous patterns in network traffic and access logs, improving incident response capabilities.

Process automation and the use of AI agents are transforming how companies approach cybersecurity. For example, AI agents can analyze thousands of security events in real time, identify suspicious behaviors, and trigger automated responses such as IP blocking or credential rotation. This technology aligns with CISA's recommendations to implement robust and tailored logging that can detect potential intrusions. Combined with Business Intelligence (BI) tools like Power BI, organizations can visualize security dashboards integrating vulnerability, patch, and authentication event data, facilitating informed decision-making.

However, cybersecurity is not limited to technology. Companies must adopt a holistic approach that includes ongoing staff training, access policies based on the principle of least privilege, and periodic audits. Developers of custom applications, like those at Q2BSTUDIO, integrate security controls from the design phase to mitigate common risks such as SQL injection, buffer overflows, or deserialization issues. Precisely, the SharePoint vulnerabilities highlighted by CISA involve insecure deserialization techniques, a problem that can be avoided through secure coding practices and the use of updated libraries.

CISA's alert comes at a time when the cyber threat landscape is becoming increasingly complex. Attackers are not only targeting known vulnerabilities but also developing exploits for newly discovered flaws, as demonstrated by CVE-2026-45659, whose active exploitation was confirmed just days after its disclosure. This underscores the importance of maintaining an agile update cycle and having a prepared incident response team. Organizations that have not yet migrated to the cloud or maintain hybrid infrastructures must prioritize the security of their on-premises systems, especially those like SharePoint that are frequent attack targets.

In summary, CISA's recommendation is clear: do not wait to become a victim of an attack. The combination of security patches, hardening configurations, continuous monitoring, and the adoption of advanced technologies like AI and cloud computing can make a difference. Companies like Q2BSTUDIO support their clients in this process, offering everything from cybersecurity consulting to the development of custom solutions that integrate AI agents for early threat detection. Cybersecurity is not a destination but a continuous journey that requires investment, knowledge, and collaboration.

For more information on how to protect your SharePoint infrastructure or implement advanced cybersecurity solutions, contact our team of experts. Prevention is the best defense.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.