← Back to Daily Briefing

CISA has added several Microsoft SharePoint on-premises vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog, signaling active weaponization. The attack surface includes critical RCE via insecure deserialization (CVE-2026-58644, CVSS 9.8) and unauthenticated remote exploitation via CVE-2026-56164. These flaws enable attackers to establish initial footholds, facilitating lateral movement toward Domain Controllers and backup systems for full infrastructure encryption. Remediation requires immediate patching, AMSI integration, and the rotation of SharePoint machine keys to neutralize persistent access.

  • Vulnerability Landscape: Active Exploitation

    • CISA has transitioned multiple SharePoint flaws to the KEV catalog, confirming a shift from theoretical risk to active exploitation in the wild.
    • A significant discrepancy exists between CVSS scores and real-world risk, specifically for CVE-2026-56164 (CVSS 5.3), which permits unauthenticated remote access.
    • CVE-2026-45659, previously categorized by Microsoft as "exploitation less likely," has been confirmed as actively exploited.
  • Technical Deep Dive: Attack Vectors

    • CVE-2026-58644 is a high-severity critical deserialization vulnerability leading to Remote Code Execution (RCE) with a CVSS of 9.8.
    • CVE-2026-332201 involves improper input validation, which allows for network-based spoofing.
    • These vulnerabilities target internet-facing on-premises instances, providing a low-barrier entry point for external threat actors.
  • Impact and Risk Trajectory

    • The typical attack chain follows a high-risk path: initial SharePoint foothold $\rightarrow$ lateral movement $\rightarrow$ compromise of Domain Controllers and backups.
    • Successful exploitation often culminates in full-scale infrastructure encryption via ransomware.
    • CISA has mandated aggressive remediation timelines for Federal Civilian Executive Branch (FCEB) agencies, with critical deadlines extending to July 19, 2026.
  • Mitigation and Defense-in-Depth

    • Deploy Microsoft's recommended AMSI (Antimalware Scan Interface) integration to identify and block malicious requests.
    • Perform a mandatory rotation of SharePoint machine keys to invalidate potential attacker persistence and session tokens.
    • Implement strict network segmentation to isolate SharePoint servers from the rest of the internal environment, specifically protecting backup repositories.
    • Maintain strict compliance with Binding Operational Directive (BOD) 22-01 to ensure timely patching of known exploited flaws.

Related posts

  1. computerworld.com — CISA urges immediate SharePoint hardening as exploits mount
  2. CISA Cybersecurity Advisories — CISA Urges SharePoint Hardening After New Exploitations
  3. csoonline.com — CISA urges immediate SharePoint hardening as exploits mount
  4. feeds.feedburner.com — CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
  5. Reddit
  6. Mescomputing
  7. Aonl
  8. Beazley
  9. SecurityWeek — CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities

LINK COPIED TO CLIPBOARD