Recent findings reveal that vulnerabilities in Microsoft SharePoint Server are being actively exploited, posing significant risks such as remote code execution (RCE) and unauthorized data access. These exploits target on-premises SharePoint installations, threatening them with potential data breaches and ransomware attacks.
SharePoint Versions at Risk
The affected versions include SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Attackers are exploiting weaknesses in authentication and data processing, allowing them to penetrate corporate networks via exposed collaboration servers.
Research by Resecurity indicates that these attacks quickly escalate from initial web requests to deeper intrusions, affecting SharePoint, IIS, SQL Server, and Active Directory systems. The exploitation of these vulnerabilities remains a concern for public-facing SharePoint infrastructures.
Details of the Exploited Vulnerabilities
The critical vulnerabilities include CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, all listed in CISA’s Known Exploited Vulnerabilities catalog. These flaws enable attackers to execute remote code and bypass authentication, resulting in unauthorized access and persistent web shell installations.
Particularly concerning is the theft of ASP.NET machineKey values from SharePoint configuration files, which could allow attackers to generate trusted ViewState data, maintaining access even after initial vulnerabilities are resolved.
Mitigating the Threats
Organizations are advised to apply Microsoft’s recent security updates across all SharePoint servers promptly. It is crucial to prioritize these systems for threat hunting and incident response activities.
Additional security measures include enabling AMSI integration, using Full Request Body Scan mode, and restricting direct internet exposure. Regular monitoring of IIS, Windows Event, and SharePoint ULS logs for unusual activities is also recommended to detect potential compromises.
In case of suspected breaches, isolating affected servers and resetting credentials are essential steps. Rotating IIS machine keys should only be considered after ensuring the environment is clear of threats.
By implementing these strategies, organizations can significantly reduce the risk of SharePoint server exploits and safeguard their networks against potential cyber threats.
