GadgetLad: Look out! SharePoint’s Encountered a Risky Triplet of Vulnerabilities

Introduction

The US Cybersecurity and Infrastructure Security Agency (CISA) has called on all organizations operating SharePoint to enhance their security measures following the emergence of a concerning trio of actively exploited vulnerabilities. This alert is directed at those utilizing any supported version of SharePoint Server on-premises. Let’s delve into the technical details.

The Noteworthy Trio of Vulnerabilities

CVE-2026-32201: The Spoofing Surprise

First on the list is a spoofing vulnerability, CVE-2026-32201 (6.5), which Microsoft disclosed back in March. CISA verified that this troublesome flaw was being actively exploited as of June. Quite a predicament.

CVE-2026-45659: Remote Code Ruckus

Next, we have CVE-2026-45659 (8.8) – a remote code execution (RCE) vulnerability that emerged in June. Our colleagues at CISA are somewhat apprehensive about this one after it was confirmed to have been utilized in various attacks. Microsoft deemed the chances of exploitation as “less likely,” yet here we are!

CVE-2026-56164: Privilege Escalation Escapade

The latest entry is CVE-2026-56164 (5.3), causing quite a stir during this month’s Patch Tuesday fiasco. Keep your eyes wide open and stay vigilant.

Additional Troubling Bugs on the Horizon

Two more issues from the recent Patch Tuesday may further complicate matters. Introducing CVE-2026-55040 (9.1) and CVE-2026-58644 (9.8). Microsoft has labeled both with an “Exploitation More Likely” tag, although no one has exploited them yet.

Post-Exploitation Antics

The trio of troublesome vulnerabilities is interfering with post-exploitation activities, including stealing Internet Information Services (IIS) machine keys and employing deserialization techniques, all aimed at persistence and malware activities.

Previous Alerts and Attacks

CISA recalls an alert from August 2025 advising organizations to keep SharePoint safeguarded against “ToolShell” attacks. Attackers have been exploiting CVE-2025-49706 (6.5) and CVE-2025-49704 (8.8) in tandem to infiltrate SharePoint Servers, deploying Warlock ransomware. Microsoft observed Chinese state-affiliated groups probing ToolShell as early as July 2025.

CISA’s Recommended Defensive Measures

What actions should you take? Implement Microsoft’s latest security updates and ensure that Antimalware Scan Interface (AMSI) integration is enabled for every SharePoint web application. Avoid exposing SharePoint to the internet unless absolutely necessary, and ensure that external access to SharePoint Central Admin is restricted. CISA also emphasizes the importance of robust logging to detect exploits. Strengthen your defenses immediately.

In Conclusion

“SharePoint Security Special!”

If you’re utilizing SharePoint, it’s time to take action by applying those patches and bolstering your defenses. Don’t let these vulnerabilities undermine your operations. Stay alert and let’s fend off those cyber threats. Game on, tech champions!