< Back to all clusters
[TECHNOLOGY] · United States · 6 sources

US CISA urges urgent hardening of Microsoft SharePoint after active exploits

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory urging organizations to immediately secure on‑premises Microsoft SharePoint deployments. CISA reported that three vulnerabilities – CVE‑2026‑33220, CVE‑2026‑45659 and the newly added CVE‑2026‑56164 – are being actively exploited in the wild and have been placed in the agency’s Known Exploited Vulnerabilities (KEV) catalog.

CISA recommends applying Microsoft’s security updates, enabling Antimalware Scan Interface (AMSI) integration, hunting for indicators of compromise, rotating SharePoint machine keys, and segmenting network access to limit the impact of any compromised server. Federal Civilian Executive Branch agencies have been given three days to remediate the newly disclosed CVE‑2026‑56164 under a binding operational directive.