--===============3621881583216843464==
Content-Type: multipart/alternative; boundary="===============8414213216597838052=="
MIME-Version: 1.0
--===============8414213216597838052==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Cybersecurity and Infrastructure Security Agency (CISA)
You are subscribed to Cybersecurity Advisories for Cybersecurity and Infras= tructure Security Agency. This information has recently been updated and is=
now available.
CISA Urges SharePoint Hardening After New Exploitations [
https://www.cisa.= gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new= -exploitations ] 07/14/2026 03:30 PM EDT=20
CISA is aware of active exploitation of vulnerabilities CVE-2026-32201 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-32201 ], CVE-2026-45659 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-45659 ], and CVE-2026-56164 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-56164 ], enabling cyber threat actors t=
o gain unauthorized access to on-premises SharePoint Server instances. Thes=
e vulnerabilities affect all supported on-premises SharePoint Server versio=
ns (Subscription Edition, 2019, and 2016) and involve establishing remote c= ode execution (RCE) and post-exploitation activities, such as stealing Inte= rnet Information Services (IIS) machine keys and performing deserialization=
techniques, to gain persistence and deploy malware. Organizations should m= onitor affected SharePoint Servers closely for any signs of exploitation or=
unusual activity.
Additionally, the following newly disclosed CVEs are not yet known to have = been exploited, but Microsoft has identified them as posing a potential ris=
k if left unpatched:
* CVE-2026-55040 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55040 ]=20
* CVE-2026-58644 [
https://www.cve.org/CVERecord?id=3DCVE-2026-58644 ]=20
CISA urges organizations to detect and remediate a potential compromise by = implementing the following recommendations:
* Apply the latest patches and security updates from Microsoft, verify th=
at installation completes successfully, and shorten patching cycles when po= ssible.=20
* Verify that Antimalware Scan Interface (AMSI) integration is enabled fo=
r each SharePoint web application. Follow Microsoft=E2=80=99s Configure AMS=
I integration with SharePoint Server [
https://learn.microsoft.com/en-us/sh= arepoint/security-for-sharepoint-server/configure-amsi-integration ] guidan=
ce to ensure proper configuration and select the =E2=80=9CFull Mode=E2=80=
=9D option for the Request Body Scan Mode, where feasible. When compromise =
is expected, use the following AMSI and Microsoft Defender Antivirus (MDAV)=
detections, and implement your organization=E2=80=99s incident response pl=
an for any positive detections:
* AMSI: Exploit:Script/SuspSignoutReqBody.A=C2=A0=E2=80=93 request body s= canning; SharePoint Server Subscription only; Microsoft has blocked observe=
d attempts.=20
* AMSI: Exploit:Script/ToolPaneAuthBypass.A =E2=80=93 request header scan= ning; SharePoint Server 2016, 2019, and Subscription Edition.=20
* AMSI: Exploit:Script/ToolPaneAuthBypass.C =E2=80=93 RCE coverage; Share= Point Server 2016, 2019, and Subscription Edition.=20
* MDAV: Backdoor:MSIL/LeakFang.A!dha=C2=A0=E2=80=93 post-exploitation act= ivity alert involving IIS-protected secrets.=20
In addition, CISA recommends that organizations implement the following Sha= rePoint Server hardening measures:
* Before rotating IIS machine keys, hunt for and remediate any intrusion = artifacts, including machine-key harvesters, that could allow for the keys =
to be stolen again. Review Microsoft=E2=80=99s Improved ASP.NET view state = security and key management [
https://learn.microsoft.com/en-us/sharepoint/= security-for-sharepoint-server/improved-asp-net-view-state-security-key-man= agement#automatic-machine-key-rotation ] for best practices.=20
* Establish tailored logging mechanisms to detect and monitor exploitatio=
n activities. Review telemetry for anomalous requests, suspicious SharePoin=
t worker-process activity, webshells, and machine-key access. For more info= rmation, see CISA=E2=80=99s Best Practices for Event Logging and Threat Det= ection [
https://www.cisa.gov/resources-tools/resources/best-practices-even= t-logging-and-threat-detection ].=20
* Avoid exposing SharePoint Servers directly to the internet unless neces= sary; and if necessary, only configure a SharePoint Server behind a Layer 7=
reverse proxy or equivalent application-layer security control that requir=
es authentication and can inspect and filter requests.=20
* Block external access to SharePoint Central Administration, restrict fa=
rm and database communications to required systems, and review Microsoft=E2= =80=99s SharePoint Server security-hardening guidance [
https://learn.micro= soft.com/en-us/sharepoint/security-for-sharepoint-server/security-hardening=
] for role-specific ports, services, and Web.config settings.=20
CISA urges users and administrators to review the Alert UPDATE: Microsoft R= eleases Guidance on Exploitation of SharePoint Vulnerabilities [
https://le= arn.microsoft.com/en-us/sharepoint/security-for-sharepoint-server/security-= hardening ] and apply necessary updates.
CISA added the following vulnerabilities to its Known Exploited Vulnerabili= ties (KEV) Catalog [
https://www.cisa.gov/known-exploited-vulnerabilities-c= atalog ]: CVE-2026-32201 on April 14, 2026; CVE-2026-45659 on July 1, 2026;=
and CVE-2026-56164 on July 14, 2026.
*Note*: CISA may update this Alert to reflect new guidance issued by CISA o=
r other parties.
Organizations should report incidents or anomalous activity to CISA via CIS= A=E2=80=99s 24/7 Operations Center at
contact@cisa.dhs.gov or 1-844-Say-CIS=
A (1-844-729-2472).
Please share your thoughts with us through this anonymous survey [
https://= cisasurvey.gov1.qualtrics.com/jfe/form/SV_9n4TtB8uttUPaM6?Source=3DGovDeliv= erySharePointHardeningAlert ]. We appreciate your feedback.
This product is provided subject to this=C2=A0Notification [
https://www.ci= sa.gov/notification ]=C2=A0and this=C2=A0Privacy & Use [
https://www.cisa.g= ov/privacy-policy ] policy.
body { font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight=
: normal; font-style: normal; color: #333333; }=20
Having trouble viewing this message?=C2=A0View it as a webpage [
https://co= ntent.govdelivery.com/accounts/USDHSCISA/bulletins/4208511 ].=C2=A0 [ https= ://content.govdelivery.com/accounts/USDHS/bulletins/292141e ]
You are subscribed to updates from the Cybersecurity and Infrastructure Sec= urity Agency [
https://www.cisa.gov ] (CISA)
Manage Subscriptions [
https://public.govdelivery.com/accounts/USDHSCISA/su= bscriber/edit?preferences=3Dtrue#tab1 ]=C2=A0=C2=A0|=C2=A0=C2=A0Privacy Pol= icy [
https://www.cisa.gov/privacy-policy ]=C2=A0=C2=A0|=C2=A0 Help [ https= ://subscriberhelp.granicus.com/s/article/Subscriber-Help-Center ] [ https:/= /insights.govdelivery.com/Communications/Subscriber_Help_Center ]
Connect with CISA:=20
Facebook [
https://www.facebook.com/CISA ]=C2=A0 |=C2=A0 Twitter [
https://= twitter.com/CISAgov ]=C2=A0 |=C2=A0 Instagram [
https://Instagram.com/cisag=
ov ]=C2=A0 |=C2=A0 LinkedIn [
https://www.linkedin.com/company/cybersecurit= y-and-infrastructure-security-agency ]=C2=A0 |=C2=A0=C2=A0 YouTube [ https:= //www.youtube.com/channel/UCxyq9roe-npgzrVwbpoAy0A ]
________________________________________________________________________
This email was sent to
cisa@toolazy.synchro.net using Granicus Communicatio=
ns Cloud, on behalf of: Cybersecurity and Infrastructure Security Agency = =C2=B7 707 17th St, Suite 4000 =C2=B7 Denver, CO 80202 GovDelivery logo [ h= ttps://granicus.com/solution/digital-communication-engagement/ ]=20
body .abe-column-block { min-height: 5px; } table.gd_combo_table img {margi= n-left:10px; margin-right:10px;} table.gd_combo_table div.govd_image_displa=
y img, table.gd_combo_table td.gd_combo_image_cell img {margin-left:0px; ma= rgin-right:0px;}
--===============8414213216597838052==
Content-Type: text/html; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"
http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns=3D"
http://www.w3.org/1999/xhtml" xml:lang=3D"en" lang=3D"en"> <head>
<title> CISA Urges SharePoint Hardening After New Exploitations
</title>
</head>
<body style=3D"">
<table width=3D"700" border=3D"0" cellspacing=3D"0" cellpadding=3D"0"=
align=3D"center">
<tr>
<td>
<!--[if (gte mso 9)|(IE)]>
<table style=3D"display:none"><tr><td><a name=3D"gd_top" id=3D"gd_top"></= a></td></tr></table>
<![endif]-->
<a name=3D"gd_top" id=3D"gd_top"></a>
=20
<p><img src=3D"
https://content.govdelivery.com/attachments/fancy_images/U= SDHSCISA/2020/06/3486054/05152023-gov-delivery-banner-copy_original.png" al= t=3D"Cybersecurity and Infrastructure Security Agency (CISA)" title=3D"" wi= dth=3D"600" height=3D"100"></p>
<p>You are subscribed to Cybersecurity Advisories for Cybersecurity and I= nfrastructure Security Agency. This information has recently been updated a=
nd is now available.</p>
<div class=3D"rss_title" style=3D"font-weight: bold; font-size: 120%; margi=
n: 0 0 0.3em; padding: 0;"><a href=3D"
https://www.cisa.gov/news-events/aler= ts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations" targ= et=3D"_blank" title=3D"CISA Urges SharePoint Hardening After New Exploitati= ons" rel=3D"noopener">CISA Urges SharePoint Hardening After New Exploitatio= ns</a></div>
<div class=3D"rss_pub_date" style=3D"font-size: 90%; font-style: italic; co= lor: #666666; margin: 0 0 0.3em; padding: 0;">07/14/2026 03:30 PM EDT</div> <div class=3D"l-page-section l-page-section--rich-text csaf-imported">
<div class=3D"l-constrain">
<div class=3D"l-page-section__content">
<p>CISA is aware of active exploitation of vulnerabilities <a href=3D"https= ://www.cve.org/CVERecord?id=3DCVE-2026-32201" target=3D"_blank" title=3D"CV= E-2026-32201" rel=3D"noopener">CVE-2026-32201</a>, <a href=3D"
https://www.c= ve.org/CVERecord?id=3DCVE-2026-45659" target=3D"_blank" title=3D"CVE-2026-4= 5659" rel=3D"noopener">CVE-2026-45659</a>, and <a href=3D"
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-56164" target=3D"_blank" title=3D"CVE-2026-56164=
" rel=3D"noopener">CVE-2026-56164</a>, enabling cyber threat actors to gain=
unauthorized access to on-premises SharePoint Server instances. These vuln= erabilities affect all supported on-premises SharePoint Server versions (Su= bscription Edition, 2019, and 2016) and involve establishing remote code ex= ecution (RCE) and post-exploitation activities, such as stealing Internet I= nformation Services (IIS) machine keys and performing deserialization techn= iques, to gain persistence and deploy malware. Organizations should monitor=
affected SharePoint Servers closely for any signs of exploitation or unusu=
al activity.</p>
<p>Additionally, the following newly disclosed CVEs are not yet known to ha=
ve been exploited, but Microsoft has identified them as posing a potential = risk if left unpatched:</p>
<li><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55040" target=3D= "_blank" title=3D"CVE-2026-55040" rel=3D"noopener">CVE-2026-55040</a></li> <li><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58644" target=3D= "_blank" title=3D"CVE-2026-58644" rel=3D"noopener">CVE-2026-58644</a></li> </ul>
<p>CISA urges organizations to detect and remediate a potential compromise =
by implementing the following recommendations:</p>
<li>Apply the latest patches and security updates from Microsoft, verify th=
at installation completes successfully, and shorten patching cycles when po= ssible.</li>
<li>Verify that Antimalware Scan Interface (AMSI) integration is enabled fo=
r each SharePoint web application. Follow Microsoft=E2=80=99s <a href=3D"ht= tps://learn.microsoft.com/en-us/sharepoint/security-for-sharepoint-server/c= onfigure-amsi-integration" target=3D"_blank" title=3D"Configure AMSI integr= ation with SharePoint Server" rel=3D"noopener">Configure AMSI integration w= ith SharePoint Server</a> guidance to ensure proper configuration and selec=
t the =E2=80=9CFull Mode=E2=80=9D option for the Request Body Scan Mode, wh= ere feasible. When compromise is expected, use the following AMSI and Micro= soft Defender Antivirus (MDAV) detections, and implement your organization= =E2=80=99s incident response plan for any positive detections:<br>
<li>AMSI: <font size=3D"4"><code><span>Exploit:Script/SuspSignoutReqBody.A<= /span></code></font>=C2=A0=E2=80=93 request body scanning; SharePoint Serve=
r Subscription only; Microsoft has blocked observed attempts.</li> <li>AMSI:<font size=3D"4"><code> Exploit:Script/ToolPaneAuthBypass.A</code>= </font> =E2=80=93 request header scanning; SharePoint Server 2016, 2019, an=
d Subscription Edition.</li>
<li>AMSI:<font size=3D"4"><code> Exploit:Script/ToolPaneAuthBypass.C</code>= </font> =E2=80=93 RCE coverage; SharePoint Server 2016, 2019, and Subscript= ion Edition.</li>
<li>MD<font size=3D"3">AV</font><font size=3D"4"><font size=3D"3">: <font s= ize=3D"4"><code>Backdoor:MSIL/LeakFang.A!dha</code></font></font></font><sp=
an style=3D"font-size: 11.0pt; font-family: 'Franklin Gothic Book',sans-ser= if;">=C2=A0</span>=E2=80=93 post-exploita<font size=3D"3">tion activity ale=
rt involving</font> IIS-protected secrets.</li>
</ul>
</li>
</ul>
<p style=3D"margin-left: .25in;">In addition, CISA recommends that organiza= tions implement the following SharePoint Server hardening measures:</p>
<li>Before rotating IIS machine keys, hunt for and remediate any intrusion = artifacts, including machine-key harvesters, that could allow for the keys =
to be stolen again. Review Microsoft=E2=80=99s <a href=3D"
https://learn.mic= rosoft.com/en-us/sharepoint/security-for-sharepoint-server/improved-asp-net= -view-state-security-key-management#automatic-machine-key-rotation" target= =3D"_blank" title=3D"Improved ASP.NET view state security and key managemen=
t" rel=3D"noopener">Improved ASP.NET view state security and key management=
</a> for best practices.</li>
<li>Establish tailored logging mechanisms to detect and monitor exploitatio=
n activities. Review telemetry for anomalous requests, suspicious SharePoin=
t worker-process activity, webshells, and machine-key access. For more info= rmation, see CISA=E2=80=99s <a href=3D"
https://www.cisa.gov/resources-tools= /resources/best-practices-event-logging-and-threat-detection" target=3D"_bl= ank" title=3D"Best Practices for Event Logging and Threat Detection" rel=3D= "noopener">Best Practices for Event Logging and Threat Detection</a>.</li> <li>Avoid exposing SharePoint Servers directly to the internet unless neces= sary; and if necessary, only configure a SharePoint Server behind a Layer 7=
reverse proxy or equivalent application-layer security control that requir=
es authentication and can inspect and filter requests.</li>
<li>Block external access to SharePoint Central Administration, restrict fa=
rm and database communications to required systems, and review <a href=3D"h= ttps://learn.microsoft.com/en-us/sharepoint/security-for-sharepoint-server/= security-hardening" target=3D"_blank" title=3D"Microsoft=E2=80=99s SharePoi=
nt Server security-hardening guidance" rel=3D"noopener">Microsoft=E2=80=99s=
SharePoint Server security-hardening guidance</a> for role-specific ports,=
services, and <font size=3D"4"><code>Web.config</code></font> settings.</l=
</ul>
<p style=3D"margin-left: .25in;">CISA urges users and administrators to rev= iew the Alert <a href=3D"
https://learn.microsoft.com/en-us/sharepoint/secur= ity-for-sharepoint-server/security-hardening" target=3D"_blank" title=3D"UP= DATE: Microsoft Releases Guidance on Exploitation of SharePoint Vulnerabili= ties" rel=3D"noopener">UPDATE: Microsoft Releases Guidance on Exploitation =
of SharePoint Vulnerabilities</a> and apply necessary updates<span style=3D= "font-family: 'Arial',sans-serif;">.</span></p>
<p>CISA added the following vulnerabilities to its <a href=3D"
https://www.c= isa.gov/known-exploited-vulnerabilities-catalog" target=3D"_blank" title=3D= "Known Exploited Vulnerabilities (KEV) Catalog" rel=3D"noopener">Known Expl= oited Vulnerabilities (KEV) Catalog</a>: CVE-2026-32201 on April 14, 2026; = CVE-2026-45659 on July 1, 2026; and CVE-2026-56164 on July 14, 2026.</p> <p><strong>Note</strong>: CISA may update this Alert to reflect new guidanc=
e issued by CISA or other parties.</p>
<p>Organizations should report incidents or anomalous activity to CISA via = CISA=E2=80=99s 24/7 Operations Center at
contact@cisa.dhs.gov or 1-844-Say-= CISA (1-844-729-2472).</p>
<p>Please share your thoughts with us through <a href=3D"
https://cisasurvey= .gov1.qualtrics.com/jfe/form/SV_9n4TtB8uttUPaM6?Source=3DGovDeliverySharePo= intHardeningAlert" target=3D"_blank" title=3D"this anonymous survey" rel=3D= "noopener">this anonymous survey</a>. We appreciate your feedback.</p>
<p>This product is provided subject to this=C2=A0<a href=3D"
https://www.cis= a.gov/notification" target=3D"_blank" title=3D"Follow link" rel=3D"noopener= ">Notification</a>=C2=A0and this=C2=A0<a href=3D"
https://www.cisa.gov/priva= cy-policy" target=3D"_blank" title=3D"Follow link" rel=3D"noopener">Privacy=
& Use</a> policy.</p>
</div>
</div>
</div>
<style>body {
font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight: norma=
l; font-style: normal; color: #333333;
}
</style>
=20
<div id=3D"mail_footer">
<p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; colo=
r: #757575;">Having trouble viewing this message?=C2=A0</span><a href=3D"ht= tps://content.govdelivery.com/accounts/USDHSCISA/bulletins/4208511" target= =3D"_blank" rel=3D"noopener">View it as a webpage</a>.=C2=A0<a href=3D"http= s://content.govdelivery.com/accounts/USDHS/bulletins/292141e" target=3D"_bl= ank" rel=3D"noopener"></a><span style=3D"font-size: 10.0pt; color: #757575;= "></span></p>
<p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; color: #= 757575;">You are subscribed to updates from the </span><a href=3D"
https://w= ww.cisa.gov"><span style=3D"font-size: 10.0pt;">Cybersecurity and Infrastru= cture Security Agency</span></a><span style=3D"font-size: 10.0pt; color: #7= 57575;"> (CISA)<br></span><a href=3D"
https://public.govdelivery.com/account= s/USDHSCISA/subscriber/edit?preferences=3Dtrue#tab1" target=3D"_blank" rel= =3D"noopener"><span style=3D"font-size: 10.0pt; color: #00568c;">Manage Sub= scriptions</span></a>=C2=A0=C2=A0<span style=3D"font-size: 10.0pt; color: #= 757575;">|=C2=A0=C2=A0</span><a href=3D"
https://www.cisa.gov/privacy-policy=
" target=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; colo=
r: #00568c;">Privacy Policy</span></a><span style=3D"font-size: 10.0pt; col= or: #757575;">=C2=A0=C2=A0|=C2=A0 <a href=3D"
https://subscriberhelp.granicu= s.com/s/article/Subscriber-Help-Center" target=3D"_blank" rel=3D"noopener">= Help</a><a href=3D"
https://insights.govdelivery.com/Communications/Subscrib= er_Help_Center" target=3D"_blank" rel=3D"noopener"></a></span><span style= =3D"font-size: 10.0pt; color: #757575;"></span></p>
<p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; color: #= 757575;">Connect with CISA: <br></span><a href=3D"
https://www.facebook.com/= CISA" target=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; = color: #00568c;">Facebook</span></a><span style=3D"font-size: 10.0pt; color=
: #757575;">=C2=A0 |=C2=A0 </span><a href=3D"
https://twitter.com/CISAgov" t= arget=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; color: = #00568c;">Twitter</span></a><span style=3D"font-size: 10.0pt; color: #75757= 5;">=C2=A0 |=C2=A0 </span><a href=3D"
https://Instagram.com/cisagov" target= =3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; color: #0056= 8c;">Instagram</span></a><span style=3D"font-size: 10.0pt; color: #757575;"= >=C2=A0 |=C2=A0 </span><a href=3D"
https://www.linkedin.com/company/cybersec= urity-and-infrastructure-security-agency" target=3D"_blank" rel=3D"noopener= "><span style=3D"font-size: 10.0pt; color: #00568c;">LinkedIn</span></a><sp=
an style=3D"font-size: 10.0pt; color: #757575;">=C2=A0 |=C2=A0=C2=A0 </span= ><a href=3D"
https://www.youtube.com/channel/UCxyq9roe-npgzrVwbpoAy0A" targe= t=3D"_self"><span style=3D"font-size: 10.0pt; color: #00568c;">YouTube</spa= n></a><span style=3D"font-size: 10.0pt; color: #757575;"></span></p>
</div>
<div id=3D"tagline">
<hr>
<table style=3D"width: 100%;" border=3D"0" cellspacing=3D"0" cellpadding=3D=
<tbody>
<td style=3D"color: #757575; font-size: 10px; font-family: Arial;" width=3D= "89%">This email was sent to
cisa@toolazy.synchro.net using Granicus Commun= ications Cloud, on behalf of: Cybersecurity and Infrastructure Security Age= ncy =C2=B7 707 17th St, Suite 4000 =C2=B7 Denver, CO 80202</td>
<td align=3D"right" width=3D"11%"><a href=3D"
https://granicus.com/solution/= digital-communication-engagement/" target=3D"_blank" rel=3D"noopener"><img = src=3D"
https://content.govdelivery.com/images/govd-logo-dark.png" border=3D= "0" alt=3D"GovDelivery logo" width=3D"115"></a></td>
</tr>
</tbody>
</table>
<style type=3D"text/css">body .abe-column-block { min-height: 5px; } table.= gd_combo_table img {margin-left:10px; margin-right:10px;} table.gd_combo_ta= ble div.govd_image_display img, table.gd_combo_table td.gd_combo_image_cell=
img {margin-left:0px; margin-right:0px;}</style>
</div>
</td>
</tr>
</table>
<img alt=3D"" src=3D"
https://links-2.govdelivery.com/CI0/0101019f6241cc25-0= ab47cb8-be8f-4abf-87ea-6c38a4eb31e8-000000/nJgAN8lwpTbDmNkeiERUQgsTiwABkj4Z= O6utJd3YiG8=3D452" style=3D"display: none; width: 1px; height: 1px;">
</body>
</html>
--===============8414213216597838052==--
--===============3621881583216843464==--