Critical Microsoft SharePoint RCE Vulnerabilities Under Active Attack
Key Takeaways Multiple critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server are actively being exploited. These exploits affect SharePoint Server Subscription Edition,...
Key Takeaways
- Multiple critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server are actively being exploited.
- These exploits affect SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016.
- Attackers are leveraging these flaws to deploy persistent web shells and steal cryptographic keys, potentially leading to widespread network compromise.
- The vulnerabilities, including CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, are listed in CISA’s Known Exploited Vulnerabilities catalog.
- Immediate patching with Microsoft’s July 2026 security updates and proactive threat hunting are crucial for mitigation.
Threat actors are actively exploiting critical vulnerabilities within Microsoft SharePoint Server deployments, enabling remote code execution (RCE), the installation of persistent web shells, and the theft of cryptographic keys from exposed systems. This campaign poses a significant risk to organizations utilizing on-premises SharePoint, potentially leading to severe consequences such as data exfiltration, broader network compromise, ransomware deployment, and sustained unauthorized access.
Table Of Content
The vulnerabilities impact SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Attackers are chaining multiple vulnerabilities, including authentication bypass, unsafe data processing, and input-validation flaws. This allows them to transform an internet-accessible SharePoint server into a critical entry point for deeper penetration into an organization’s internal network.
Cybersecurity firm Resecurity has been tracking this activity, noting the speed with which attackers can escalate from an initial web request to compromising SharePoint, IIS, SQL Server, and Active Directory-connected resources. Resecurity said in a report that the theft of IIS machine keys is a particularly concerning aspect of these attacks, as it can enable attackers to maintain access even after the initial vulnerability used for entry has been patched.
This ongoing campaign highlights the persistent risk associated with public-facing SharePoint infrastructure. A single unpatched server, often containing sensitive organizational documents and possessing trusted connections to other critical business systems, can become a gateway for extensive compromise. This situation echoes previous concerns regarding deserialization weaknesses and other RCE vulnerabilities that have impacted the platform.
Microsoft SharePoint Vulnerabilities
The actively exploited vulnerabilities, CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, have been added to CISA’s Known Exploited Vulnerabilities catalog. Specifically, CVE-2026-45659 enables a site member to achieve remote code execution, while CVE-2026-56164 allows an unauthenticated attacker to bypass authentication and access critical functions.
Upon successfully achieving code execution, attackers typically deploy a web shell onto the compromised SharePoint server. This web shell serves as a persistent backdoor, allowing them to execute arbitrary commands, upload additional malicious files, and maintain long-term access to the network. This tactic is consistent with other web shell attacks targeting IIS environments, where a compromised web server becomes a covert and resilient foothold within an organization’s infrastructure.
A particularly dangerous consequence of these exploits is the theft of ASP.NET machineKey values, which are stored in SharePoint configuration files. These keys are fundamental for protecting application data, and their compromise can enable attackers to forge trusted ViewState data or authentication tokens. This capability allows them to retain access even if the initial web shell is detected and removed. The Resecurity report also warns that attackers might install malicious IIS modules that load with worker processes, ensuring persistence even through server restarts. Once a SharePoint farm is compromised, the elevated privileges of the service account can be leveraged to access databases, discover further credentials, and expand control over domain resources and other internal systems.
What You Should Do
- Apply Security Updates Immediately: Organizations must apply Microsoft’s July 2026 SharePoint security updates across all servers in their farm without delay. Verify that the updated builds are successfully installed.
- Prioritize Incident Response for Exposed Servers: Treat any unpatched, internet-exposed SharePoint servers as high-priority targets for incident response and proactive threat hunting activities.
- Enable AMSI Integration: Enable Antimalware Scan Interface (AMSI) integration for all web applications, and, where feasible, configure it to use Full Request Body Scan mode.
- Harden Network
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.