logo

Microsoft SharePoint Vulnerabilities Actively Exploited for RCE, Web Shells, and IIS Key Theft

ID: cc7329c9-4c50-57db-9b44-375650711aac

STIX ID: report--cc7329c9-4c50-57db-9b44-375650711aac

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Tushar Subhra Dutta

...
...

This report details active exploitation of multiple SharePoint Server vulnerabilities (including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) enabling remote code execution, web shell deployment, theft of ASP.NET machineKey values, and installation of malicious IIS modules; attackers can use these footholds to move from a compromised internet-facing SharePoint server to databases, IIS, and Active Directory resources. The report includes IoCs, detection and hardening recommendations (patching, AMSI full-body scans, log review, isolation, credential resets), and notes the issues are listed in CISA’s Known Exploited Vulnerabilities catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.