we_are_coded.by CODE · The world, decoded
БГ
Security

A SharePoint hole is being actively exploited, and Microsoft had underrated it

CISASecurity

Attackers are already using a hole in on-premises SharePoint (Microsoft's document software) - in real attacks, not in theory. CISA added it to the list of actively exploited vulnerabilities and set a patching deadline. Microsoft had rated it as unlikely to be attacked.

In short
  • A code-execution vulnerability in on-premises SharePoint is being actively exploited.
  • CISA added it to the catalog of actively exploited holes and set a federal patching deadline.
  • Affected: SharePoint 2016/2019/Subscription (on-premises); cloud SharePoint Online is not.
Checked on3 July 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

A vulnerability in on-premises SharePoint Server allows code execution by an attacker with valid credentials (username and password) and ordinary site-member rights. It's not theory - it's already being used in real attacks. That's why CISA added it to the catalog of actively exploited holes and set a patching deadline for federal agencies.

The facts: SharePoint Server 2016, 2019 and Subscription Edition (on-premises installs, not cloud SharePoint Online) are affected. Valid credentials and site-member rights are needed, which is a low bar for an insider attacker or a stolen account. Microsoft initially rated the risk as low; reality proved it wrong.

I'll allow myself an opinion here: what matters is the gap between the vendor's assessment and what attackers actually do. 'Unlikely to be exploited' doesn't mean safe. It just means no one has tried it publicly yet. If CISA sets a deadline, someone has already tried it successfully.

Running on-premises SharePoint? Stop reading. Act. The patch is available, the clock is running. Cloud installs are off the hook, but the forgotten on-premises server is exactly the classic open door.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→CISA - Known Exploited Vulnerabilities
Original: https://wearecoded.com/en/articles/sharepoint-rce-cisa-kev.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news