Cybersecurity

CISA keeps adding SharePoint flaws to its must-patch list

Future Technology ยท 24 July 2026

CISA has confirmed active exploitation of four vulnerabilities affecting on-premises Microsoft SharePoint Server, adding CVE-2026-32201, CVE-2026-45659, CVE-2026-56164 and CVE-2026-58644 to its Known Exploited Vulnerabilities catalog. That's on top of the SharePoint flaws already flagged and patched earlier in the summer.

The vulnerabilities affect all supported on-premises SharePoint versions, Subscription Edition, 2019 and 2016, and let attackers establish remote code execution, steal Internet Information Services machine keys, and use deserialisation techniques to gain persistence and deploy malware. CISA has also issued fresh guidance urging organisations to harden SharePoint deployments generally, not just patch the specific CVEs.

Why this matters

Cloud-hosted SharePoint Online is not affected. This is specifically about on-premises deployments, which are increasingly rare outside larger enterprises and government but still common enough to be a repeated target this year. If your organisation runs SharePoint Server on its own infrastructure, this is not a 'patch when convenient' item, it's the priority for this weekend's maintenance window.