CISA sounds alarm over trio of exploited SharePoint flaws

https://image.theregister.com/5242008.jpg?imageId=5242008&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Three bugs are under active attack, and two more critical holes could add to the pain

The US Cybersecurity and Infrastructure Security Agency (CISA) has urged all organizations running SharePoint to harden their defenses after the disclosure of actively exploited vulnerabilities.

The warning applies to those running any supported version of SharePoint Server on-prem, with three vulnerabilities of particular interest cited.

A spoofing bug, CVE-2026-32201 (6.5), was the first to be mentioned. Microsoft disclosed it in March and CISA confirmed it was being actively exploited in June.

Additionally, CISA appears concerned by CVE-2026-45659 (8.8) – a remote code execution (RCE) flaw made public in June and confirmed as being actively used in attacks last week after Microsoft said exploitation was "less likely."

The most recent of the three, CVE-2026-56164 (5.3), a privilege escalation flaw, was one of the 622 bugs that featured in this month's record Patch Tuesday.

CISA...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more