CISA Urges SharePoint Hardening After New Exploitations

2026-07-15T13:24:16Zcf1abca3c546b037dfa0f0e08b9ec35a8d91d4a517b7ae119471f21a3fefbcef
ADFSAMSIAdobe ColdFusionCISACiscoKnown Exploited VulnerabilitiesRCESharePointSonicWalldeserializationpatchingvulnerability managementweb‑upload vulnerabilities

What happened

CISA warns of active exploitation against multiple on‑premises Microsoft SharePoint Server vulnerabilities (notably CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) that enable remote code execution and post‑exploitation actions (e.g., stealing IIS machine keys, deserialization attacks, persistence and malware deployment). CISA urges rapid patching, AMSI integration verification, and increased monitoring. In parallel, CISA added numerous vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog — including SonicWall SMA (CVE-2026-15409, CVE-2026-15410), Microsoft ADFS (CVE-2026-56155

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
cf1abca3c546b037dfa0f0e08b9ec35a8d91d4a517b7ae119471f21a3fefbcef
Enrichment time
2026-07-15T13:24:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.