Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Microsoft 365 Flaw Lets Attackers Send Malware via Calendar Invites
July 21, 2026
Furtex Linux Toolkit Aids Post-Exploitation and Evasion for Red Teams
July 21, 2026
Critical Windows Vulnerability Blinds EDR, Bypasses AMSI, AppLocker, Sysmon
July 20, 2026
Home/CyberSecurity News/Critical Microsoft SharePoint RCE Vulnerabilities Under Active Attack
CyberSecurity News

Critical Microsoft SharePoint RCE Vulnerabilities Under Active Attack

Key Takeaways Multiple critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server are actively being exploited. These exploits affect SharePoint Server Subscription Edition,...

Jennifer sherman
Jennifer sherman
July 20, 2026 3 Min Read
5 0

Key Takeaways

  • Multiple critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server are actively being exploited.
  • These exploits affect SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016.
  • Attackers are leveraging these flaws to deploy persistent web shells and steal cryptographic keys, potentially leading to widespread network compromise.
  • The vulnerabilities, including CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, are listed in CISA’s Known Exploited Vulnerabilities catalog.
  • Immediate patching with Microsoft’s July 2026 security updates and proactive threat hunting are crucial for mitigation.

Threat actors are actively exploiting critical vulnerabilities within Microsoft SharePoint Server deployments, enabling remote code execution (RCE), the installation of persistent web shells, and the theft of cryptographic keys from exposed systems. This campaign poses a significant risk to organizations utilizing on-premises SharePoint, potentially leading to severe consequences such as data exfiltration, broader network compromise, ransomware deployment, and sustained unauthorized access.

Table Of Content

  • Key Takeaways
  • Microsoft SharePoint Vulnerabilities
  • What You Should Do

The vulnerabilities impact SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Attackers are chaining multiple vulnerabilities, including authentication bypass, unsafe data processing, and input-validation flaws. This allows them to transform an internet-accessible SharePoint server into a critical entry point for deeper penetration into an organization’s internal network.

Cybersecurity firm Resecurity has been tracking this activity, noting the speed with which attackers can escalate from an initial web request to compromising SharePoint, IIS, SQL Server, and Active Directory-connected resources. Resecurity said in a report that the theft of IIS machine keys is a particularly concerning aspect of these attacks, as it can enable attackers to maintain access even after the initial vulnerability used for entry has been patched.

This ongoing campaign highlights the persistent risk associated with public-facing SharePoint infrastructure. A single unpatched server, often containing sensitive organizational documents and possessing trusted connections to other critical business systems, can become a gateway for extensive compromise. This situation echoes previous concerns regarding deserialization weaknesses and other RCE vulnerabilities that have impacted the platform.

Microsoft SharePoint Vulnerabilities

The actively exploited vulnerabilities, CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, have been added to CISA’s Known Exploited Vulnerabilities catalog. Specifically, CVE-2026-45659 enables a site member to achieve remote code execution, while CVE-2026-56164 allows an unauthenticated attacker to bypass authentication and access critical functions.

Upon successfully achieving code execution, attackers typically deploy a web shell onto the compromised SharePoint server. This web shell serves as a persistent backdoor, allowing them to execute arbitrary commands, upload additional malicious files, and maintain long-term access to the network. This tactic is consistent with other web shell attacks targeting IIS environments, where a compromised web server becomes a covert and resilient foothold within an organization’s infrastructure.

A particularly dangerous consequence of these exploits is the theft of ASP.NET machineKey values, which are stored in SharePoint configuration files. These keys are fundamental for protecting application data, and their compromise can enable attackers to forge trusted ViewState data or authentication tokens. This capability allows them to retain access even if the initial web shell is detected and removed. The Resecurity report also warns that attackers might install malicious IIS modules that load with worker processes, ensuring persistence even through server restarts. Once a SharePoint farm is compromised, the elevated privileges of the service account can be leveraged to access databases, discover further credentials, and expand control over domain resources and other internal systems.

What You Should Do

  • Apply Security Updates Immediately: Organizations must apply Microsoft’s July 2026 SharePoint security updates across all servers in their farm without delay. Verify that the updated builds are successfully installed.
  • Prioritize Incident Response for Exposed Servers: Treat any unpatched, internet-exposed SharePoint servers as high-priority targets for incident response and proactive threat hunting activities.
  • Enable AMSI Integration: Enable Antimalware Scan Interface (AMSI) integration for all web applications, and, where feasible, configure it to use Full Request Body Scan mode.
  • Harden Network

    Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

    Tags:

    AttackBreachCVEExploitPatchransomwareSecurityThreatVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

GoldenEyeDog Hackers Breach DigiCert, Steal Code-Signing Certificates

Next Post

Critical Kimai Docker Flaw Lets Attackers Forge Cookies, Take Over Accounts

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical RCE in Wp2shell Could Fetch $500,000 on Exploit Markets
July 20, 2026
ClickFix Campaign Delivers TELEPUZ Malware with 36 Remote Commands
July 20, 2026
Microsoft Ends OneDrive Sync App Updates for Windows 10
July 20, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us