logo

Actively Exploited SharePoint Flaws Let Hackers Deploy Web Shells and Steal IIS Machine Keys

ID: 818accf6-118f-52e1-9f64-3988705306db

STIX ID: report--818accf6-118f-52e1-9f64-3988705306db

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Varshini

...
...

Multiple on-premises Microsoft SharePoint Server vulnerabilities (including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164 and additional CVEs addressed in July 2026) are being actively exploited to bypass authentication, trigger unsafe deserialization, and achieve remote code execution; attackers deploy ASP.NET web shells, steal IIS machine keys to maintain long-term access, and can pivot to backend systems. Organizations are advised to immediately patch affected servers, investigate for web shells and altered configuration files, rotate machine keys only after confirming systems are clean, and monitor for indicators such as new/modified .aspx, .dll, .js, and .txt files in SharePoint and IIS directories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.