CVE Tools

CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities

SecurityWeekBy Ionut Arghire

Reported exploitedMicrosoft SharePointCreative Mail WordPress Plugin

Our summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about actively exploited vulnerabilities in Microsoft SharePoint, including the zero-day flaw CVE-2026-56164. This privilege escalation bug allows unauthenticated attackers to execute malicious actions remotely and was recently patched by Microsoft. CISA added it to its Known Exploited Vulnerabilities catalog and urges organizations to apply updates immediately. Additional critical flaws like CVE-2026-55040 and CVE-2026-58644 were also addressed in recent security updates. These issues could lead to remote code execution and data theft if left unpatched.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store