A SharePoint Server vulnerability is being actively exploited right now, and CISA has told federal agencies to patch it immediately. If your Boston business still runs an on-premises SharePoint Server (not SharePoint Online, which is unaffected), you need to check your patch status this week, not next quarter.
- CISA added SharePoint Server flaw CVE-2026-45659 to its Known Exploited Vulnerabilities catalog on July 1, 2026, after confirming active attacks.
- A second SharePoint Server flaw, CVE-2026-56164, was patched as part of Microsoft’s July 2026 Patch Tuesday and was also being exploited before the fix shipped.
- Both flaws affect on-premises SharePoint Server (Subscription Edition, 2019, and 2016). SharePoint Online in Microsoft 365 is not affected.
- July 2026 was Microsoft’s largest Patch Tuesday on record: 570 vulnerabilities fixed, including three zero-days.
- If you don’t know whether your business runs SharePoint Server versus SharePoint Online, that uncertainty is itself the problem to fix first.
What is actually wrong with SharePoint Server?
CVE-2026-45659 is a deserialization flaw that lets an attacker who already has basic Site Member access to a SharePoint site run arbitrary code on the server, no admin rights needed to start the attack. Microsoft shipped a patch back in May 2026, but CISA confirmed exploitation was still happening in the wild and added it to the Known Exploited Vulnerabilities catalog on July 1, giving federal agencies until July 4 to patch. CVE-2026-56164 is a separate, unrelated flaw: a missing authentication check that lets an unauthorized attacker elevate privileges over the network. Microsoft patched it in the same July 2026 update where it also fixed 570 vulnerabilities total, including three zero-days, two of which attackers were already using before a fix existed.
Does this affect your business?
Only if you run SharePoint Server on your own hardware or in a hosted server environment your IT team manages directly. Most small businesses in the Boston area use SharePoint Online as part of a Microsoft 365 subscription, and that version is not exposed to either flaw, Microsoft patches it centrally. The businesses at risk are usually ones with a legacy document management setup, an older intranet, or a line-of-business application that was built against an on-prem SharePoint farm years ago and never migrated. If you’re not sure which one you have, that’s the first thing to find out, not assume.
What should you check this week?
Confirm your SharePoint Server build number against Microsoft’s security update list and verify the July and, if you missed it, May patches are actually installed, not just downloaded. Then check whether your server is reachable from the open internet. A lot of on-prem SharePoint deployments were set up for internal use only and later opened to the internet for remote access without anyone revisiting the security posture. If internet exposure isn’t a business requirement, closing it off cuts your attack surface immediately, patched or not. Also pull your IIS and SharePoint logs for anomalous requests in June and July. CISA’s alert notes attackers used these flaws to steal IIS machine keys, which can let them forge authentication tokens and keep access even after you patch, so a clean patch alone doesn’t guarantee the intruder is gone if you were already compromised.
Why does this keep happening with on-prem software?
On-premises SharePoint Server is now old enough, and complex enough, that it draws steady attacker interest while getting less attention from the businesses running it. It’s the same dynamic we flagged with Windows Server 2016 heading toward end of support in January 2027: software that used to be a safe default is quietly becoming a liability because nobody revisits the architecture once it’s working. Cloud-hosted alternatives like SharePoint Online get patched by Microsoft without any action from you. Self-hosted software puts that job back on your team, and if there’s no one tracking Patch Tuesday releases the way we broke down in our June 2026 Patch Tuesday rundown, gaps like this are how a five-year-old server becomes the entry point for a ransomware crew.
Frequently asked questions
Is SharePoint Online affected by this vulnerability?
No. Both CVE-2026-45659 and CVE-2026-56164 affect on-premises SharePoint Server only (Subscription Edition, 2019, and 2016). SharePoint Online, included with Microsoft 365, is managed and patched by Microsoft and is not exposed to either flaw.
How do I know if my SharePoint Server was already compromised?
Check IIS and SharePoint logs for unusual requests from May onward, particularly to admin or API endpoints from unfamiliar IP ranges. Because attackers have used this flaw to steal IIS machine keys, a straightforward patch doesn’t rule out prior compromise. If you find anything suspicious, treat it as an incident and get a security review before assuming you’re clear.
What if we can’t patch right away?
Restrict access to the SharePoint Server to your internal network or a VPN, disable public internet exposure if it isn’t essential, and enable Antimalware Scan Interface (AMSI) with full request body scanning, which Microsoft lists as a mitigation for CVE-2026-56164. These reduce risk but are not a substitute for installing the patch.
Should we just move to SharePoint Online instead of patching?
For many small businesses, yes, migrating off on-prem SharePoint removes this entire category of risk going forward. It’s not a same-day fix, so patch and lock down your current server first, then plan the migration on a realistic timeline rather than rushing it.
Running an unpatched SharePoint Server on-prem? Don’t wait for someone to find it first. Boston Managed IT will check your setup, confirm what’s exposed, and give you a clear fix plan in a free 15-minute review. Call (617) 322-5155 or book at bostonmit.com/contact.
— Boston Managed IT