Skip to content
EternaEdge

Cyber threat

SharePoint is a target again. The lesson is exposure, not patching

17 July 2026 · 2m read · By EternaEdge

On July 14, CISA issued an alert urging organizations to immediately patch and harden on-premises Microsoft SharePoint servers, citing active exploitation of multiple vulnerabilities — CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 — affecting SharePoint Server 2016, 2019, and Subscription Edition. Per CISA and reporting in The Register, attackers bypassed authentication, achieved remote code execution, and stole IIS machine keys to persist after patching. Additional SharePoint flaws have followed onto the Known Exploited Vulnerabilities catalog since.

If this feels familiar, it should. The 2025 “ToolShell” wave ran the same play against the same platform. A year later, internet-exposed collaboration infrastructure remains one of the most reliable enterprise entry points an adversary can ask for.

Patching is necessary. It is not the lesson

The recurring SharePoint story is not about any single CVE. It is about what the platform holds and where it sits: document stores full of contracts, engineering data, and program information, reachable from the internet, often self-hosted precisely because the data was considered too sensitive for the cloud. Machine-key theft makes the point sharply — a patched server is not a clean server if the keys walked out first.

Three questions that matter more than patch status

  • Do you know every internet-facing instance you own — including the ones inherited through acquisitions and the ones a business unit stood up without telling anyone?
  • If a server was exposed during the exploitation window, has anyone looked for persistence — rotated machine keys, audited new accounts — rather than just applying the update?
  • What did the compromised store actually contain, and who would want it? A SharePoint full of program documents is an intelligence target, not an IT asset.

That last question is where cyber threat intelligence has to meet counterintelligence. Knowing an exploit exists is table stakes; knowing your exposure — which assets, which data, which adversaries have historically wanted it — is what turns an advisory into a decision. STRATUM — Cyber Threat approaches the problem from that direction: attack-surface mapping and shadow-IT discovery prioritized by mission impact rather than CVE count, alongside the security stack you already run — it is not a SIEM replacement. Analysts make the response calls; the platform is designed to make sure they are looking at the right exposure first.

There will be another SharePoint advisory, or its equivalent for the next platform. The organizations that ride it out calmly will be the ones that already knew what they had exposed and what it was worth to an adversary.

Next step

See it run on your domains of protection.

A demo walks the full arc — signal to case to defensible record — with the domains you protect in the room.