Attackers are reportedly exploiting vulnerabilities in on-premises Microsoft SharePoint Server to gain unauthorized access, execute code, and establish persistence. Resecurity describes six flaws affecting SharePoint Server Subscription Edition, 2019, and 2016, and reports active exploitation and CISA Known Exploited Vulnerabilities catalog inclusion for CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644. SharePoint Online and Microsoft 365 are reportedly unaffected. Previdian identifies CVE-2026-45659 as an untrusted-data deserialization vulnerability patched in May, and separately reports exploitation of CVE-2026-50522 following July security updates. However, conflicting advisories describe different mechanisms and severity scores for CVE-2026-50522, warranting validation against Microsoft's authoritative guidance.
Reported attacker activity includes deploying web shells, stealing ASP.NET machine keys, and maintaining access through forged ViewState payloads or malicious IIS modules. Patching alone may not eliminate an existing compromise, because stolen keys and implanted persistence can survive updates. Organizations should patch every SharePoint farm server, investigate for web shells and malicious modules, rotate machine keys after cleanup, and rotate affected credentials. Additional recommended defenses include enabling AMSI request-body scanning and restricting network exposure. The reports do not attribute the activity to a specific threat group; Resecurity's illustrative domain-compromise scenario is explicitly fictional, not evidence of an actual breach.

See which actors are running it and whether you're in range.
13 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2026-58644 to its Known Exploited Vulnerabilities Catalog after Microsoft confirmed active exploitation. The flaw permits unauthenticated remote code execution through deserialization of untrusted data.
CISA added CVE-2026-56164 to its exploited-vulnerability catalog and issued an advisory reporting exploitation of CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164. The advisory described unauthorized access, remote code execution, IIS machine-key theft, and persistence through deserialization techniques.
Microsoft published fixes for CVE-2026-56164, CVE-2026-55040, CVE-2026-58644, and CVE-2026-50522. The vulnerabilities affect on-premises SharePoint Server rather than SharePoint Online or Microsoft 365.
CISA added the SharePoint deserialization vulnerability CVE-2026-45659 to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation.
Microsoft released updates addressing CVE-2026-45659, a deserialization vulnerability that allows an authenticated SharePoint Site Member to execute code remotely.
CISA listed the SharePoint spoofing vulnerability CVE-2026-32201 in its Known Exploited Vulnerabilities Catalog, reflecting confirmed exploitation.
The Resecurity report credits Rapid7 with discovering a two-vulnerability unauthenticated remote code execution chain involving CVE-2026-55040. It does not specify when the discovery occurred.
CERT-EU reported that watchTowr observed active exploitation after identifying proof-of-concept code on July 20. The supplied content does not specify the date of that subsequent observation.
CERT-EU updated its SharePoint advisory, placing CVE-2026-50522 within the ongoing series of actively exploited on-premises vulnerabilities. It strongly recommended immediate updates and credential rotation for affected assets.
CISA added CVE-2026-50522 to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation.
BleepingComputer reported that attackers were exploiting CVE-2026-50522 to steal SharePoint machine keys. The stolen keys could let attackers retain access after servers were patched.
According to CERT-EU, watchTowr identified public proof-of-concept exploit code for CVE-2026-50522, an unauthenticated SharePoint remote code execution vulnerability.
Zero Day Initiative published ZDI-26-412 and ZDI-26-413, describing unauthenticated SharePoint remote code execution through deserialization and improper cryptographic signature verification, respectively. Both excerpts assign CVE-2026-50522 a score of 8.1, conflicting with the 9.8 score reported elsewhere in the supplied content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
resecurity.com
Open sourceprevidian.com
Open sourceprevidian.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.