Federal cybersecurity regulators have updated an emergency operational alert following ongoing active wild exploitation targeting enterprise document management platforms. Threat actors are chaining authentication bypass flaws with deserialization vectors to gain full remote control over on-premises collaboration hosts.
The alert focuses on active exploitation of CVE-2026-55040 and CVE-2026-58644 across Microsoft SharePoint Server 2016, 2019, and Subscription Edition environments. Incident telemetry indicates threat groups are exploiting weak authentication checks to bypass edge filters, execute untrusted object deserialization, steal IIS machine keys, and deploy persistent web shell backdoors. CISA has reinforced directives requiring enterprise administrators to place all internet-facing SharePoint nodes behind authenticated Layer 7 reverse proxies.
Compromising a central collaboration server provides attackers with an unmonitored command post inside the corporate network. Armed with stolen machine keys and system-level execution rights, threat actors can decrypt application traffic, access internal document vaults, and execute lateral movement routines targeting adjacent directory controllers.
– Isolate all on-premises SharePoint Server farms behind Layer 7 reverse proxies that require strict pre-authentication.
– Apply the latest cumulative security patches released by Microsoft across all SharePoint deployment tiers immediately.
– Inspect web server configuration files and registry hives for signs of machine key harvesting or unauthorized modifications.
– Conduct comprehensive log reviews to identify unusual deserialization exceptions or unauthorized administrative script calls.
Document repository protection requires enforcing strict network perimeter boundaries to ensure internal collaboration platforms are completely shielded from unauthenticated remote exploitation. #CodeDefence #Microsoft #SharePoint #Deserialization #AuthBypass #CISA #KEV #VulnerabilityManagement
/
