CISA Warns of Active Exploitation of Three Microsoft SharePoint Server Vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) — Threadlinqs Intelligence
As of 2026-07-15, CISA Warns of Active Exploitation of Three Microsoft SharePoint Server Vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) is a critical-severity vulnerability threat attributed to Storm-2603 (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 17 indicators of compromise.
Threat ID: TL-2026-1361 · Severity: CRITICAL · CVSS: 8.8 · Status: ACTIVE · Category: VULNERABILITY
Attribution: Storm-2603 · China · FINANCIAL
CISA is warning that attackers are actively chaining three on-premises Microsoft SharePoint Server vulnerabilities — a spoofing/auth-bypass flaw, a deserialization RCE, and a missing-authentication
On July 14-15, 2026, CISA issued an urgent advisory warning that threat actors are actively exploiting three vulnerabilities affecting on-premises Microsoft SharePoint Server: CVE-2026-32201 (spoofing/authentication bypass via improper input validation, CVSS 6.5), CVE-2026-45659 (deserialization-of-untrusted-data remote code execution, CVSS 8.8, CWE-502), and CVE-2026-56164 (missing authentication for a critical function leading to elevation of privilege, CVSS 5.3, CWE-1220). All three affect on-premises SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016; SharePoint Online is not affected because Microsoft directly operates and patches that cloud service.
CVE-2026-32201 was patched April 14, 2026, and added to the CISA KEV catalog on that date; a public exploit (B1tBit/CVE-2026-32201-exploit) shows the flaw is triggered via crafted POST requests to SharePoint notification endpoints (e.g. /_layouts/15/notify.aspx) using a manipulated sender-override parameter, enabling reflected XSS in the security context of the SharePoint site — usable for phishing, credential theft, and spoofed authentication prompts. CVE-2026-45659 was patched May 12, 2026 (KB5002863, KB5002868, KB5002870) and added to KEV July 1, 2026 with a 3-day federal remediation deadline; it allows an attacker authenticated with only low Site Member privileges to submit serialized objects that SharePoint reconstructs without adequate validation, achieving remote code execution in the context of the IIS worker process (w3wp.exe). CVE-2026-56164 was disclosed and patched July 14-15, 2026 (Patch Tuesday, part of a record 570-622 CVE release) and immediately added to KEV the same day; it lets an unauthenticated attacker exploit a missing-authentication check over the network to elevate privileges with no user interaction.
Observed post-exploitation activity chains these bugs together: initial code execution leads to theft of ASP.NET/IIS machine keys, which attackers use to forge trusted view-state tokens and maintain authentication-bypass persistence even after the underlying vulnerability is patched — CISA explicitly warns that machine-key rotation alone is insufficient without first hunting for and removing machine-key harvesting implants. Attackers have deployed illegitimate .aspx web shells into SharePoint LAYOUTS directories (historically named similarly to spinstall0.aspx from the 2025 ToolShell campaign), then layered in redundant remote-access channels — Velociraptor (living-off-the-land use of a legitimate DFIR tool to blend in), Cloudflare Tunnels, Zoho Assist remote-access sessions, and SSH connections established through Visual Studio Code's remote extension — to survive incident-response cleanup of any single channel. Privilege escalation has included creation of new local and domain administrator accounts, and defense evasion via a vulnerable signed driver (NSecKrnl.sys) used to tamper with EDR/AV visibility. This activity mirrors the TTPs of Storm-2603 (aka GOLD SALEM), a China-based actor Microsoft has linked to prior SharePoint (ToolShell, CVE-2025-53770/53771) exploitation that culminated in deployment of Warlock ransomware via DLL search-order hijacking; Microsoft has also linked the broader 2025 ToolShell wave to additional China-nexus groups Linen Typhoon (APT27) and Violet Typhoon.
Shadowserver scanning found close to 10,000 internet-exposed on-premises SharePoint servers, with more than 800 still unpatched against CVE-2026-32201 and CVE-2026-45659 as of the CISA advisory. Federal civilian agencies were given until July 17, 2026 to remediate under BOD 26-04. Two related SharePoint vulnerabilities disclosed in the same patch wave, CVE-2026-55040 and CVE-2026-58644, were patched but not confirmed as actively exploited and are tracked separately. CISA recommends immediate patching, enabling AMSI integration with Windows Defender Antivirus (and setting SharePoint's Request Body Scan mode to Full), pla
Weaknesses (CWE)
CWE-502, CWE-1220, CWE-20
Target sectors: government administration, finance, health, education, technology, criticalinfrastructure
Target regions: North America, Europe, Asia-Pacific, Global
Detections & IOCs
As of 2026-07-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 17 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, T1595, T1190, T1078, T1203, T1059, T1505, T1505, T1136, T1136, T1133