CISA Urges SharePoint Hardening After New Exploitations
2026-07-15T13:24:16Z•cf1abca3c546b037dfa0f0e08b9ec35a8d91d4a517b7ae119471f21a3fefbcef
ADFSAMSIAdobe ColdFusionCISACiscoKnown Exploited VulnerabilitiesRCESharePointSonicWalldeserializationpatchingvulnerability managementweb‑upload vulnerabilities
What happened
CISA warns of active exploitation against multiple on‑premises Microsoft SharePoint Server vulnerabilities (notably CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) that enable remote code execution and post‑exploitation actions (e.g., stealing IIS machine keys, deserialization attacks, persistence and malware deployment). CISA urges rapid patching, AMSI integration verification, and increased monitoring. In parallel, CISA added numerous vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog — including SonicWall SMA (CVE-2026-15409, CVE-2026-15410), Microsoft ADFS (CVE-2026-56155
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- cf1abca3c546b037dfa0f0e08b9ec35a8d91d4a517b7ae119471f21a3fefbcef
- Enrichment time
- 2026-07-15T13:24:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.