Forum Discussion
Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
On July 14, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) published an alert confirming active exploitation of three on-premises SharePoint Server vulnerabilities: CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164. The alert noted that these flaws had been used to gain unauthorized access to SharePoint deployments across all supported on-premises versions and flagged two additional high-risk vulnerabilities, CVE-2026-55040 and CVE-2026-58644, as not yet exploited but warranting immediate patching. However in an update to the security advisory on July 15, Microsoft confirmed CVE-2026-58644 has been exploited in the wild.
Five Microsoft SharePoint Server vulnerabilities are covered in CISA’s alert: Four with confirmed active exploitation and one newly disclosed high-severity flaw that Microsoft assesses as “Exploitation More Likely” according to Microsoft's Exploitability Index. All five affect all supported on-premises SharePoint Server versions: Subscription Edition, 2019, and 2016.
|
CVE |
Description |
CVSSv3 |
VPR |
|---|---|---|---|
|
Microsoft SharePoint Server Spoofing Vulnerability |
6.5 |
7.2 | |
|
Microsoft SharePoint Remote Code Execution Vulnerability |
8.8 |
9.4 | |
|
Microsoft SharePoint Server Elevation of Privilege Vulnerability |
9.8 - NVD 5.3 - Microsoft |
9.5 | |
|
Microsoft SharePoint Server Security Feature Bypass Vulnerability |
9.1 |
7.3 | |
|
Microsoft SharePoint Server Remote Code Execution Vulnerability |
9.8 |
7.9 |
*Please note: Tenable’s Vulnerability Priority Rating (VPR) scores are calculated nightly. This blog post was published on July 16 and reflects VPR at that time.
For more information about these vulnerabilities, including the availability of patches and Tenable product coverage, please visit our FAQ blog.