SOC status: Operational/Continuous monitoring active

Acronis MDR / XDR available +230 5254 7558

CriticalAdvisoryTLP: CLEARCBN-2026-023 · 16 Jul 2026

Three SharePoint flaws chained on-premises, with machine-key theft that outlives the patch

Attackers are chaining a missing-authentication bug, a deserialisation bug and a spoofing bug against on-premises SharePoint, then stealing IIS machine keys so they can forge their own payloads afterwards. One of the three is flagged for ransomware use.

At a glance

Affected

On-premises Microsoft SharePoint Server 2016, 2019 and Subscription Edition. SharePoint Online is not affected. Note that 2016 and 2019 left extended support on 14 July 2026.

Impact

Unauthenticated foothold on an internet-reachable SharePoint server, escalating to code execution, cryptographic persistence via stolen machine keys, and lateral movement toward domain compromise.

Action

Patch to 16.0.5561.1001 (2016), 16.0.10417.20175 (2019) or 16.0.19725.20434 (Subscription Edition), run AMSI in Full Mode, and rotate IIS machine keys wherever compromise is possible.

Client status

No on-premises SharePoint remains in our managed estates. Clients still running 2016 or 2019 now need a migration plan, not a patch cycle — extended support ended in July.

Detail

Three separate defects, used together. CVE-2026-56164 is a function that should have required authentication and did not, letting an unauthenticated attacker on the network raise privileges. CVE-2026-45659 deserialises untrusted data into code execution once some access exists. CVE-2026-32201 enables spoofing through weak input validation. Individually they are ordinary; chained against an internet-facing SharePoint farm they are a full compromise.

Machine keys are the persistence mechanism to worry about

The step that matters most for recovery is what attackers do after the initial access: they lift the IIS machine keys. Those keys are what SharePoint uses to sign and encrypt __VIEWSTATE and other serialised data. Hold them and you can craft payloads the server will accept as its own — indefinitely, and regardless of whether the original vulnerability is patched.

So the remediation has two parts, and the second one is the one organisations skip. Apply the July updates, then rotate the machine keys on any farm that was exposed. A patched SharePoint with the attacker's copy of your signing keys is not a recovered SharePoint.

The end-of-support problem underneath

SharePoint Server 2016 and 2019 reached the end of extended support on 14 July 2026 — the same Patch Tuesday that carried these fixes. Organisations running those versions received one of the last updates they will ever get. Anyone in that position should read this advisory as a deadline for migration rather than as a maintenance task, because the next chain of this kind will not come with a patch.

Microsoft credited the discovery of CVE-2026-56164 to Mandiant incident responders and Google's FLARE team, which tells you the finding came out of real intrusions rather than a research programme. No threat actor has been named publicly, but CISA flags CVE-2026-45659 as used in known ransomware campaigns.

If you find evidence of this activity, do not begin remediation before preserving evidence — console and appliance audit logs are frequently short-retention and will roll off. Acronis MDR provides around-the-clock detection and response for covered estates; otherwise reach us through the contact page and we will advise on preservation before containment.

Sources

Cybernalyst's analysis and recommendations are our own. The underlying research is credited below — please read the original reporting.

  1. CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server VulnerabilitiesResearch Special Operations·Tenable·16 July 2026
  2. CISA sounds alarm over trio of exploited SharePoint flawsConnor Jones·The Register·15 July 2026
  3. Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active AttackSwati Khandelwal·The Hacker News·14 July 2026