The Cybersecurity and Infrastructure Security Agency issued an emergency advisory on July 15, 2026, alerting organizations that three SharePoint flaws are being actively exploited. The notice also highlighted two additional critical vulnerabilities that remain unpatched, raising the risk of further compromise across government and private sectors.
The agency’s warning follows reports of threat actors leveraging the three flaws to execute remote code, steal credentials, and deploy ransomware. Microsoft has released patches for the exploited bugs, but many installations remain vulnerable due to delayed updates. CISA stresses that the unpatched critical holes could be weaponized soon, urging immediate remediation and continuous monitoring.
Since early June, security teams have observed a surge in intrusion attempts targeting SharePoint servers worldwide. Attackers exploit the vulnerabilities to bypass authentication and gain administrative privileges. „We see sophisticated groups using these bugs to move laterally within networks,” said a CISA spokesperson. The agency estimates that thousands of organizations may already be compromised, though exact numbers are still being compiled. Microsoft’s advisory recommends applying the latest security updates, disabling unnecessary services, and enforcing multi‑factor authentication to reduce exposure.
The advisory also flags two newly disclosed critical flaws that have not yet been exploited in the wild. These weaknesses affect the same component of SharePoint but require a different attack chain, potentially allowing attackers to execute arbitrary code without user interaction. Experts warn that once these gaps become active, they could amplify the current wave of attacks, especially against entities that have not yet applied the recent patches. CISA advises all SharePoint users to prioritize the pending updates, conduct thorough vulnerability scans, and prepare incident response plans in case of breach.
The combined impact of the exploited and unpatched vulnerabilities could disrupt business operations, expose sensitive data, and increase ransomware payouts. Agencies and corporations are urged to treat the advisory as a top‑priority directive, coordinating with IT teams to close the gaps swiftly. Continued vigilance and rapid patch deployment will be essential to prevent the threat landscape from worsening.
What immediate steps should organizations take? Apply the latest SharePoint patches, enforce multi‑factor authentication, and run comprehensive scans to identify any lingering exploit activity.
Can the two critical flaws be mitigated before they are exploited? Yes, by installing the forthcoming updates as soon as they are released and by limiting external access to SharePoint services.
How does CISA monitor the exploitation of these vulnerabilities? CISA collaborates with industry partners, collects telemetry from security tools, and issues alerts when patterns of malicious activity emerge.