Desk live·
ForensicPost
Cloud/Exploitation/File 26-0714b

CISA Tells SharePoint Operators to Hunt Before They Rotate Keys

Five CVEs under active exploitation against every supported on-premises version, and stolen machine keys that keep working after the patch. The order of operations in the guidance is the interesting part: look for the intruder first, because rotating the keys destroys the evidence that they were there.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetOn-premises SharePoint operators
ActorUnattributed
D. Kennedy11 min readConfidence: high3 sources reviewed

CISA published guidance on 14 July 2026 urging operators of on-premises SharePoint Server to harden their deployments, citing active exploitation of CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644 and CVE-2026-50522. The vulnerabilities affect all supported on-premises versions — Subscription Edition, 2019 and 2016 — and were added to the Known Exploited Vulnerabilities catalogue across five separate dates between April and 22 July 2026.

The described activity is remote code execution followed by post-exploitation: theft of IIS machine keys and deserialisation techniques used to establish persistence and deploy malware.

The Ordering Instruction Is The Story

The guidance tells operators to patch, enable the Antimalware Scan Interface, hunt for intrusion artefacts, and rotate machine keys — and it puts the hunting before the rotation.

That ordering is not incidental. Rotating a stolen key is the remediation, and it also invalidates the forged material that would show the key had been used. Do it first and the environment is safe and unreadable; the organisation has closed the door and thrown away the record of who came through it.

A Patch Does Not Evict

A machine key is not a vulnerability. It is a secret the server uses to decide what it will trust, and an attacker holding one can forge authentication and application-state material the patched server accepts exactly as it accepted the old.

This corpus has filed that distinction three times now: at 25-0723, where a SharePoint chain stole machine keys that kept working after the update; at 24-0110, where mitigation was explicitly not eviction; and at 23-0518, where Barracuda concluded that patching an appliance was insufficient and told customers to replace the hardware. Patching stops the leak. It does not remove whoever came through it.

The Second July In A Row

The corpus recorded the ToolShell chain against on-premises SharePoint in July 2025 at 25-0719, confirmed under exploitation a day later and reaching around 150 organisations.

The same product, the same class of flaw and the same key-theft follow-through have now produced a federal hardening alert in two consecutive Julys. The advisory’s recommendation not to expose SharePoint to the internet unless it sits behind an authenticated reverse proxy is an admission about where the durable fix lies, and it is not in the patch cycle.

No victim organisations are named in this file, and no count of affected deployments exists. The corpus records at 26-0802 that a quarter of its files establish no entry route; this is the opposite problem — the route is documented in detail and the population that walked through it is unknown.

How we reported this

Built on reporting of CISA’s 14 July 2026 alert and of the KEV catalogue additions, together with vendor analysis of the vulnerabilities. The CVE identifiers, the affected version list, the characterisation of the post-exploitation activity and the recommended actions are CISA’s as reported; this desk was unable to retrieve the alert page directly and relies on reporting of it, which is why the file is graded high on the advisory’s existence and content rather than on primary text. No victim organisations are named and no figure for affected deployments is asserted — none was published. No indicators or exploit detail are reproduced. Corrections: corrections@forensicpost.com.

Sources
  1. CISA warns that multiple vulnerabilities in SharePoint are under exploitationCybersecurity Dive
  2. CVE-2026-32201, CVE-2026-45659, CVE-2026-56164 FAQ: SharePoint Server exploitationTenable
  3. CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEVThe Hacker News
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary