Future TechnologyFuture Technology
Security

SharePoint Zero-Days Are Under Active Attack. Patch Today.

· 4 min read · By Future Technology

Key takeaways

  • Four on-prem SharePoint flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644) are being exploited right now.
  • They allow remote code execution and theft of IIS machine keys for long-term persistence.
  • Subscription Edition, 2019 and 2016 are affected; cloud SharePoint Online is not.
  • Apply Microsoft patches and rotate machine keys today, not next week.

A SharePoint zero day 2026 warning is the kind of thing IT teams dread, and this week they got four at once. CISA has confirmed that four flaws in on-premises SharePoint Server are being actively exploited, which is the security world saying attackers are already using them, not that they might one day. If your company runs SharePoint on its own servers, this is a today job.

The bugs carry the labels CVE-2026-32201, CVE-2026-45659, CVE-2026-56164 and CVE-2026-58644. Chained together they let an attacker reach remote code execution, which means running their own commands on your server without ever logging in. Worse, the attack steals the IIS machine keys, the secret values that SharePoint uses to trust requests. Once someone has those keys they can forge access and quietly walk back in even after you patch, so cleaning up is not just a matter of installing the update.

Every supported version is exposed

Every supported on-premises version is in scope: Subscription Edition, 2019 and 2016. The one piece of good news is that SharePoint Online, the cloud version Microsoft hosts for you, is not affected here. This is very much a problem for the servers sitting inside company data centres and cupboards, which is exactly where a lot of sensitive internal documents live.

Why SharePoint keeps getting hit

Why does this keep happening to SharePoint? Because it is huge, it is old, and it sits deep inside corporate networks with links to email, identity and file storage. Crack the front door and you are often standing in the middle of the building. That combination makes it a favourite target, and it is why a single bypass gets treated as an emergency rather than a footnote. We covered an earlier SharePoint remote code execution bug only days ago, and the pattern is the same.

What to do today

If you run on-prem SharePoint, the plan is short. Apply the latest Microsoft security updates now. Rotate the IIS machine keys so any stolen ones become useless. Then hunt for signs someone already visited, because active exploitation means the window has been open for a while. CISA has published hardening guidance worth following line by line.

This is the same pattern we keep seeing across the industry, where the platforms holding the most valuable data are also the slowest to patch. It is not glamorous work, but it is the difference between a quiet weekend and a breach notification. For more on how the big platform fights are reshaping access online, see our pieces on the Cloudflare AI crawler policy and the Apple and OpenAI trade secrets lawsuit.

Read next

Get the briefing, free

The biggest tech story, explained in 3 minutes every weekday. Choose your briefings →

Free. No spam. Unsubscribe in one click.