CISA published guidance on 14 July 2026 urging operators of on-premises SharePoint Server to harden their deployments, citing active exploitation of CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644 and CVE-2026-50522. The vulnerabilities affect all supported on-premises versions — Subscription Edition, 2019 and 2016 — and were added to the Known Exploited Vulnerabilities catalogue across five separate dates between April and 22 July 2026.
The described activity is remote code execution followed by post-exploitation: theft of IIS machine keys and deserialisation techniques used to establish persistence and deploy malware.
The Ordering Instruction Is The Story
The guidance tells operators to patch, enable the Antimalware Scan Interface, hunt for intrusion artefacts, and rotate machine keys — and it puts the hunting before the rotation.
That ordering is not incidental. Rotating a stolen key is the remediation, and it also invalidates the forged material that would show the key had been used. Do it first and the environment is safe and unreadable; the organisation has closed the door and thrown away the record of who came through it.
A Patch Does Not Evict
A machine key is not a vulnerability. It is a secret the server uses to decide what it will trust, and an attacker holding one can forge authentication and application-state material the patched server accepts exactly as it accepted the old.
This corpus has filed that distinction three times now: at 25-0723, where a SharePoint chain stole machine keys that kept working after the update; at 24-0110, where mitigation was explicitly not eviction; and at 23-0518, where Barracuda concluded that patching an appliance was insufficient and told customers to replace the hardware. Patching stops the leak. It does not remove whoever came through it.
The Second July In A Row
The corpus recorded the ToolShell chain against on-premises SharePoint in July 2025 at 25-0719, confirmed under exploitation a day later and reaching around 150 organisations.
The same product, the same class of flaw and the same key-theft follow-through have now produced a federal hardening alert in two consecutive Julys. The advisory’s recommendation not to expose SharePoint to the internet unless it sits behind an authenticated reverse proxy is an admission about where the durable fix lies, and it is not in the patch cycle.
No victim organisations are named in this file, and no count of affected deployments exists. The corpus records at 26-0802 that a quarter of its files establish no entry route; this is the opposite problem — the route is documented in detail and the population that walked through it is unknown.
Built on reporting of CISA’s 14 July 2026 alert and of the KEV catalogue additions, together with vendor analysis of the vulnerabilities. The CVE identifiers, the affected version list, the characterisation of the post-exploitation activity and the recommended actions are CISA’s as reported; this desk was unable to retrieve the alert page directly and relies on reporting of it, which is why the file is graded high on the advisory’s existence and content rather than on primary text. No victim organisations are named and no figure for affected deployments is asserted — none was published. No indicators or exploit detail are reproduced. Corrections: corrections@forensicpost.com.