CISA orders urgent patching of exploited SharePoint zero-day
CISA urged immediate patching of Microsoft SharePoint after disclosure of exploited zero-day CVE-2026-56164, adding it to KEV and directing agencies to remediate within three days.
The Cybersecurity and Infrastructure Security Agency on Tuesday directed organizations to harden and patch Microsoft SharePoint servers after disclosure of an exploited zero-day, CVE-2026-56164. The agency added the flaw to its Known Exploited Vulnerabilities catalog and instructed federal civilian agencies to remediate it within three days under Binding Operational Directive 26-04.
Microsoft included a fix for CVE-2026-56164 in its July 2026 Patch Tuesday release. CISA described the bug as a remote, unauthenticated privilege escalation that has been observed in attacks. Microsoft’s July updates also addressed two other critical SharePoint vulnerabilities, CVE-2026-55040 and CVE-2026-58644, which could allow attackers to bypass a security feature or execute arbitrary code if systems are not patched.
CISA highlighted earlier exploited SharePoint flaws: CVE-2026-32201, a spoofing vulnerability patched in April after reports of exploitation, and CVE-2026-45659, a code execution issue fixed in an out-of-band May update and added to the KEV list in early July. The agency stated the vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019 and 2016) and can be combined to achieve remote code execution and follow-on activity such as stealing Internet Information Services machine keys and using deserialization techniques to gain persistence and deploy malware.
In addition to applying Microsoft’s patches, CISA advised organizations to ensure security tools monitor all SharePoint web applications, hunt for signs of intrusion, rotate IIS machine keys when compromise is suspected, enable more detailed logging on SharePoint and related systems, remove direct internet exposure for SharePoint servers and restrict access to administration interfaces. The agency also recommended monitoring servers for unusual activity that could indicate active exploitation.
Under BOD 26-04, federal civilian executive branch agencies must meet KEV timelines for remediation; newly listed exploited vulnerabilities can require fixes within days. CISA’s rapid addition of CVE-2026-56164 to the catalog followed reports of active exploitation and set the three-day remediation requirement for federal systems.
Organizations running on-premises SharePoint are advised to prioritize the July security updates and follow CISA’s mitigation guidance.








