惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Security Archives - TechRepublic
Security Archives - TechRepublic
I
InfoQ
阮一峰的网络日志
阮一峰的网络日志
云风的 BLOG
云风的 BLOG
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
AWS News Blog
AWS News Blog
S
SegmentFault 最新的问题
T
Tailwind CSS Blog
The Hacker News
The Hacker News
GbyAI
GbyAI
P
Palo Alto Networks Blog
博客园 - 三生石上(FineUI控件)
Y
Y Combinator Blog
Stack Overflow Blog
Stack Overflow Blog
博客园 - Franky
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Cyberwarzone
Cyberwarzone
H
Help Net Security
S
Securelist
月光博客
月光博客
博客园 - 【当耐特】
T
Threatpost
T
Tenable Blog
G
GRAHAM CLULEY
博客园 - 司徒正美
I
Intezer
MyScale Blog
MyScale Blog
T
Threat Research - Cisco Blogs
P
Privacy & Cybersecurity Law Blog
The GitHub Blog
The GitHub Blog
C
CERT Recently Published Vulnerability Notes
T
Tor Project blog
Google DeepMind News
Google DeepMind News
C
Cybersecurity and Infrastructure Security Agency CISA
罗磊的独立博客
腾讯CDC
P
Privacy International News Feed
博客园_首页
The Cloudflare Blog
Cisco Talos Blog
Cisco Talos Blog
A
About on SuperTechFans
V
Vulnerabilities – Threatpost
A
Arctic Wolf
B
Blog RSS Feed
Recorded Future
Recorded Future
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google DeepMind News
Google DeepMind News
S
Security Affairs
Microsoft Security Blog
Microsoft Security Blog
L
LangChain Blog

Tenable Blog

Oracle July 2026 Critical Patch Update 1235 CVEs | Tenable® AI agent config attacks: How attackers turn trusted Dev harness files into payloads wp2shell: WordPress Core Pre-Auth RCE FAQ | Tenable® Build agentic AI security at Tenable Swarm, Black Hat 2026 SonicWall CVE-2026-15409 and CVE-2026-15410 zero-day exploited | Tenable® Understanding Anthropic’s new AI agent Claude Tag’s access model in Slack 5 reasons to integrate AppSec data with your exposure management platform July 2026 Patch Tuesday: Largest Patch Tuesday 569 CVEs FedRAMP High, IL5, and zero trust: How federal agencies can secure cloud environments OMB M-26-14: Why federal agencies must fix asset visibility first CISO’s guide to CISA BOD 26-04 and risk-based security metrics for vulnerability management How much cyber risk does AI create for organizations? 457 million security issues. Here’s what you can do about it. The Developer Credential Economy: An inside look at the Miasma worm campaign Oracle Critical Security Patch Update June 2026 | Tenable® How Tenable helps federal agencies comply with CISA BOD 26-04 Get critical cyber risk context: Understanding control validation, CTEM & Tenable One CISA BOD 26-04: Frequently asked questions about the new risk-based patching directive Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507) The June 2026 AI Executive Order: What federal agencies need to know and how Tenable can help Tenable joins Anthropic’s Project Glasswing to advance AI-era cyber defense Tenable CTO Vlad Korsunsky Q&A: Countering AI threat multipliers with AI-powered exposure management | Tenable CTO Q&A: C-suite views AI as massive threat, as cyber teams adopt exposure management to counter AI attacks Oracle May 2026 Critical Security Patch Update Addresses 35 CVEs Download pumping: New npm deception technique for supply chain attacks Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect EXPOSURE 2026 prepares cybersecurity professionals for the AI era Mini Shai-Hulud: Frequently asked questions about the TeamPCP npm and PyPI supply chain campaign CVE-2026-9082: Highly Critical SQL Injection Vulnerability in Drupal Core (SA-CORE-2026-004) Tenable One deepens third-party integrations with new Open Connector for unified risk visibility Implement agentic AI in cybersecurity with Tenable Hexa AI: Reduce cyber risk at machine speed Key findings from the Verizon DBIR 2026: Slower vulnerability remediation meets faster exploitation Frequently asked questions about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182) Bring out your dead: How agentic AI for cybersecurity helps you rid your cloud of forgotten, risky assets Fragnesia (CVE-2026-46300): Frequently asked questions about new Linux Kernel XFRM ESP-in-TCP privilege escalation Securing data centers in the agentic AI era Microsoft’s May 2026 Patch Tuesday Addresses 118 CVEs (CVE-2026-41103) Dirty Frag (CVE-2026-43284, CVE-2026-43500): Frequently asked questions about this Linux kernel privilege escalation vulnerability chain Why the approaching flood of vulnerabilities changes everything — and what to do about it The AI-vs-AI battle is already happening. Watch it live at EXPOSURE 2026. Anthropic’s CEO warns the “moment of danger” is real. But most are looking in the wrong place. Security for AI: A strategic framework for closing the AI exposure gap Vulnerability remediation: Match CVEs to asset owners in seconds with Tenable Hexa AI Bridging the gap: How to integrate Claude Security into the Tenable One Exposure Management Platform Copy Fail (CVE-2026-31431): Frequently asked questions about Linux kernel privilege escalation vulnerability Mastering agentic AI security through exposure management As the NVD scales back CVE enrichment, here’s what Tenable customers need to know Five steps to become Mythos ready Oracle April 2026 Critical Patch Update Addresses 241 CVEs Beating the Mythos clock: Using Tenable Hexa AI custom agents for automated patching Unlocking foundational visibility for cyber-physical systems with OT vulnerability management Claude Mythos: Prepare for your board’s cybersecurity questions about the latest AI model from Anthropic Microsoft’s April 2026 Patch Tuesday Addresses 163 CVEs (CVE-2026-32201) Crushing the Axios supply chain threat with Tenable Hexa AI: Use cases for agentic AI What to Know About CyberAv3ngers: The IRGC-Linked Group Targeting Critical Infrastructure CVE-2026-35616: Fortinet FortiClientEMS improper access control vulnerability exploited in the wild The developer credential economy: Why exposure data is the new front line in the supply chain war Frequently Asked Questions About the Axios npm Supply Chain Attack by North Korea-Nexus Threat Actor UNC1069 Supply chain attack on Axios npm package: Scope, impact, and remediations What’s new in Tenable Cloud Security: Custom policies, AWS ABAC, and research-driven protection Uncover prompt injection, insider threats with the Tenable One Model Refusal Detection Security for AI: A guide to managing the risks of vibe coding and AI in software development Meet Tenable Hexa AI: Agentic AI for exposure management
SharePoint CVEs FAQ: CVE-2026-56164, CVE-2026-32201, CVE-2026-45659 | Tenable®
Research Special Operations · 2026-07-17 · via Tenable Blog

Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments.

Key Takeaways

  1. CISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware for persistence.
  2. Two additional SharePoint Server vulnerabilities disclosed on July 14, 2026, CVE-2026-55040 and CVE-2026-58644, were not yet observed exploited at the time of publication, but Microsoft has flagged CVE-2026-58644 as exploited on July 15.
  3. Microsoft released patches for all five vulnerabilities and Microsoft Defender Antivirus detection signatures are available to identify exploitation activity for three of the actively exploited flaws.

Background

Tenable's Research Special Operations (RSO) team has compiled this blog to answer Frequently Asked Questions (FAQ) regarding active exploitation of Microsoft SharePoint Server vulnerabilities.

FAQ

When did CISA issue an alert about SharePoint Server exploitation?

On July 14, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) published an alert confirming active exploitation of three on-premises SharePoint Server vulnerabilities: CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164. The alert noted that these flaws had been used to gain unauthorized access to SharePoint deployments across all supported on-premises versions and flagged two additional high-risk vulnerabilities, CVE-2026-55040 and CVE-2026-58644, as not yet exploited but warranting immediate patching. However in an update to the security advisory on July 15, Microsoft confirmed CVE-2026-58644 has been exploited in the wild.

What vulnerabilities are covered in this alert?

Five Microsoft SharePoint Server vulnerabilities are covered in CISA’s alert: Four with confirmed active exploitation and one newly disclosed high-severity flaw that Microsoft assesses as “Exploitation More Likely” according to Microsoft's Exploitability Index. All five affect all supported on-premises SharePoint Server versions: Subscription Edition, 2019, and 2016.

CVEDescriptionCVSSv3VPR
CVE-2026-32201Microsoft SharePoint Server Spoofing Vulnerability6.57.2
CVE-2026-45659Microsoft SharePoint Remote Code Execution Vulnerability8.89.4
CVE-2026-56164Microsoft SharePoint Server Elevation of Privilege Vulnerability9.8 - NVD5.3 - Microsoft9.5
CVE-2026-55040Microsoft SharePoint Server Security Feature Bypass Vulnerability9.17.3
CVE-2026-58644Microsoft SharePoint Server Remote Code Execution Vulnerability9.87.9

*Please note: Tenable’s Vulnerability Priority Rating (VPR) scores are calculated nightly. This blog post was published on July 16 and reflects VPR at that time.

What do the actively exploited vulnerabilities do?

CVE-2026-32201 is a spoofing flaw rooted in improper input validation. An unauthenticated remote attacker can exploit it over a network without user interaction.

CVE-2026-45659 is a remote code execution (RCE) vulnerability involving deserialization of untrusted data. An authenticated attacker can exploit this flaw in order to execute code on an affected SharePoint server.

CVE-2026-56164 is an elevation of privilege vulnerability. An unauthenticated attacker can exploit it remotely to elevate privileges on a SharePoint Server.

CVE-2026-58644 is a RCE vulnerability that can be abused by an authenticated attacker with at least Site Owner permissions. Successful exploitation would allow the attacker to achieve code execution by exploiting a deserialization of untrusted data flaw.

What post-exploitation activity has been observed?

According to CISA, attackers have combined CVE-2026-32201, CVE-2026-45659 and CVE-2026-56164 to gain entry to on-premises SharePoint Server instances, then pursued several post-exploitation objectives: extracting IIS machine keys, leveraging deserialization techniques to establish persistence, and deploying malware. CISA notes that stolen machine keys can be used to forge requests enabling further exploitation of the server. The advisory notes that key rotation alone is not a complete remediation step, without first removing any key-harvesting artifacts.

What is CVE-2026-55040, the vulnerability that has not yet been exploited?

CVE-2026-55040 is a security feature bypass rooted in weak authentication. It was assigned a CVSSv3 score of 9.1 and rated as critical. An unauthenticated attacker can exploit it over the network, without user interaction allowing the attacker to impact both confidentiality and integrity.

Both CVE-2026-55040 and CVE-2026-58644 were disclosed on July 14, 2026, as part of Microsoft's July 2026 Patch Tuesday release. As of July 16, 2026, CVE-2026-55040 has not been observed being exploited in the wild.

What is the history of exploitation for Microsoft SharePoint Server?

Microsoft SharePoint Server has been a recurring target for threat actors across multiple years. CISA's Known Exploited Vulnerabilities (KEV) catalog contains 12 SharePoint-related entries, including seven currently known to be used in ransomware campaigns. The table below outlines prior SharePoint CVEs added to the KEV catalog.

Which threat actors are exploiting these SharePoint vulnerabilities?

As of July 16, 2026, neither CISA nor Microsoft has attributed the active exploitation of CVE-2026-32201, CVE-2026-45659, CVE-2026-56164 or CVE-2026-58644 to specific threat actors or groups.

Is there a proof-of-concept available for any of these vulnerabilities?

As of July 16, 2026, no public proofs-of-concept are available for any of the five vulnerabilities covered in this FAQ.

Are patches and mitigations available?

Microsoft released patches for all five vulnerabilities. The table below lists the fixed build numbers for each affected SharePoint version.

CVESharePoint Enterprise Server 2016SharePoint Server 2019SharePoint Server Subscription Edition
CVE-2026-3220116.0.5548.100316.0.10417.2011416.0.19725.20210
CVE-2026-4565916.0.5552.100216.0.10417.2012816.0.19725.20280
CVE-2026-5616416.0.5561.100116.0.10417.2017516.0.19725.20434
CVE-2026-5504016.0.5561.100116.0.10417.2017516.0.19725.20434
CVE-2026-5864416.0.5556.100516.0.10417.2015316.0.19725.20384

The CISA advisory and several of the Microsoft security advisories recommend enabling AMSI integration on SharePoint and IIS worker processes and setting the Request Body Scan mode to Full to allow detection of malicious POST payloads. CISA's hardening guidance also advises against direct internet exposure of SharePoint Servers and recommends restricting external access to SharePoint Central Administration.

Are there indicators of compromise?

Yes. CISA and Microsoft have published AMSI and Microsoft Defender Antivirus detection signatures for the three actively exploited vulnerabilities.

SignatureTypeScope
Exploit:Script/SuspSignoutReqBody.AAMSIRequest body scanning; SharePoint Server Subscription Edition only; Microsoft reports active exploitation attempts have been blocked
Exploit:Script/ToolPaneAuthBypass.AAMSIRequest header scanning; SharePoint Server 2016, 2019, and Subscription Edition
Exploit:Script/ToolPaneAuthBypass.CAMSIRCE coverage; SharePoint Server 2016, 2019, and Subscription Edition
Backdoor:MSIL/LeakFang.A!dhaMDAVPost-exploitation activity; IIS machine key access

CISA recommends reviewing telemetry for anomalous requests, suspicious SharePoint worker-process activity, webshells and machine-key access activity.

Has Tenable Research classified these vulnerabilities as part of Vulnerability Watch?

Yes. Tenable Research has classified CVE-2026-32201, CVE-2026-45659 and CVE-2026-56164 and CVE-2026-58644 as part of Vulnerability Watch. The designation applies to flaws with confirmed in-the-wild exploitation and the potential for widespread impact across affected organizations. We are actively tracking developments related to this activity and will update this post as new information becomes available.

Has Tenable released product coverage for these vulnerabilities?

A list of Tenable plugins can be found on the individual CVE pages:

This link will display all available plugins for these vulnerabilities, including upcoming plugins in our Plugins Pipeline.

Additionally, Tenable Attack Surface Management customers can identify external-facing assets by leveraging the built-in subscription labeled Microsoft Sharepoint Server - v1.

Get more information

Join Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.

Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.