Updated
Updated · The Register · Jul 16
CISA Flags 3 SharePoint Zero-Days as Failed Microsoft Patches Leave Servers Exposed
Updated
Updated · The Register · Jul 16

CISA Flags 3 SharePoint Zero-Days as Failed Microsoft Patches Leave Servers Exposed

3 articles · Updated · The Register · Jul 16

Summary

  • Three Microsoft SharePoint Server flaws are under active zero-day attack after earlier patches failed to fully protect on-premises deployments, prompting a fresh CISA alarm.
  • CISA added the bugs to its Known Exploited Vulnerabilities catalog and said organizations should treat them as urgent because attackers are already exploiting them in the wild.
  • The flaws include CVE-2026-32201, CVE-2026-45659 and CVE-2026-56164, with one carrying a CVSS 9.8 severity score.
  • Attackers can steal IIS machine keys, use deserialization for persistence and malware delivery, and then move laterally through sensitive internal systems.
  • The warning sharpens pressure on organizations running on-prem SharePoint to patch, harden servers and segment networks as Microsoft works to close the gaps.

Insights

Your SharePoint server is now unsupported. Are hackers exploiting a permanent, unpatchable backdoor into your network?
Hackers are stealing server keys. Why is patching your system not enough to truly lock them out?
With AI discovering more flaws, is the era of secure on-premise software finally coming to an end?