SharePoint zero-days are the story of the week — and CISA wants them patched now

If there is one thread tying this week together, it is the humble on-premises server sitting inside your network. A wave of actively exploited flaws in Microsoft SharePoint, a Patch Tuesday of record size, and a run of breaches traced back to third-party platforms all point in the same direction: the systems you own but rarely look at — and the vendors you trust with your data — are where attackers spent their week.

Key takeaways

  • On-prem SharePoint is under active attack. CISA has confirmed exploitation of multiple SharePoint Server flaws and issued a hardening advisory. If you run SharePoint on-premises, treat this as urgent.
  • Microsoft’s July Patch Tuesday was the largest on record — roughly 570 fixes, including two zero-days already being exploited (SharePoint and AD FS) and one publicly disclosed.
  • Third parties were a recurring point of failure. Ernst & Young confirmed client data was taken through a support platform, and other firms faced extortion claims tied to stolen data.
  • What to do: prioritise the SharePoint and AD FS patches, rotate exposed secrets, and confirm your incident-response and vendor-risk plans are current.

The lead story: an on-premises SharePoint exploitation wave

The most consequential development this week is the sustained, real-world exploitation of Microsoft SharePoint Server. On 14 July, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) urged organisations to harden SharePoint after new exploitation activity, and it has flagged several SharePoint flaws as being actively abused to gain unauthorised access to on-premises instances.

Why this matters beyond IT: SharePoint often sits at the centre of how an organisation stores documents, runs intranets, and manages workflows. A compromise there is rarely contained to one server. According to CISA and multiple vendor advisories, attackers have been chaining remote code execution with post-exploitation moves — stealing server machine keys and abusing them to keep access even after a patch is applied. In plain terms: patching alone may not evict an attacker who got in first.

Reporting has linked some of this activity to a threat group deploying ransomware after breaking in through SharePoint, which raises the stakes from data theft to full business disruption. We are deliberately not attributing specific incidents to specific groups here, because attribution this early is often revised — but the pattern (exploit an internet-facing server, establish persistence, then extort) is well established.

For the practitioners

This wave centres on on-premises SharePoint Server (Subscription Edition, 2019, and 2016). CISA lists several CVEs under active exploitation, including CVE-2026-56164, a missing-authentication flaw that an unauthenticated attacker can trigger remotely over the network to escalate privileges. It was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog and resolved in the July Patch Tuesday updates.

Because attackers have been harvesting IIS/ASP.NET machine keys for persistence, patching is necessary but may not be sufficient. Rotate machine keys after patching, hunt for web shells and unexpected scheduled tasks, review authentication logs, and validate that internet exposure of SharePoint is genuinely required. SharePoint Online (Microsoft 365) is not affected by the on-prem flaws.

Also worth knowing this week

Microsoft ships a record-breaking Patch Tuesday

Microsoft’s July 2026 Patch Tuesday addressed roughly 570 vulnerabilities — the largest single release on record, though exact counts vary by outlet and by how third-party fixes are tallied. Of those, two zero-days were already being exploited in attacks: the SharePoint flaw above (CVE-2026-56164) and an Active Directory Federation Services privilege-escalation issue (CVE-2026-56155). A third, a BitLocker bypass, was publicly disclosed before a fix shipped. The AD FS flaw is worth singling out for any organisation using federated sign-on, because it can hand an attacker administrator-level access to a system that underpins authentication across many other services.

Ernst & Young confirms a third-party data exposure

EY confirmed that an unauthorised third party accessed its IT support ticketing platform and downloaded client documents — reportedly including tax and investment-holding records — before the activity was detected. The detail that should give every business pause is the timeline: reporting indicates the access window spanned roughly two weeks before detection. Support and ticketing systems are easy to overlook in a security programme, yet they routinely hold sensitive attachments. If you use external support platforms, they belong in your data-inventory and monitoring scope.

Extortion claims against large enterprises

Several large organisations faced public extortion claims this week, with threat actors advertising stolen data on leak sites. In at least one case, a company stated the incident was isolated with no operational impact, while others were named on ransomware leak sites accompanied by sample records. We are treating the specifics cautiously: leak-site claims are marketing for the attacker and are frequently exaggerated or partly recycled from older breaches. The durable lesson is not any single name — it is that data exfiltration plus public pressure remains the dominant extortion model, whether or not files are ever encrypted.

So what should you actually do?

For most organisations, three actions cover the bulk of this week’s risk. First, if you run SharePoint on-premises or use AD FS, prioritise the July patches, and for SharePoint go further: rotate machine keys and hunt for signs of prior compromise rather than assuming the update closed the door. Second, bring your third-party platforms — support desks, ticketing, file-sharing, anything holding your data — into your monitoring and vendor-risk reviews, because two of this week’s incidents started there. Third, rehearse your extortion playbook now, while it is calm: know who decides, who communicates, and what “we’ve been named on a leak site” triggers internally.

None of this is dramatic, and that is the point. The week rewarded organisations with current asset inventories, disciplined patching of internet-facing systems, and a clear-eyed view of where their data actually lives.

Not sure where your on-prem and third-party exposure sits?

Secure-X helps organisations find the internet-facing systems and vendor dependencies that attackers look for first — and build a patching and response plan that holds up under pressure. If this week’s roundup raised a question about your own environment, we’re happy to talk it through.

Talk to Secure-X


Published by Secure-X. This roundup is general information, not specific security advice for your environment. For guidance tailored to your systems, get in touch.

Share the Post:

Related Posts