News·3 min read

Actively Exploited SharePoint Flaws Let Hackers Deploy Web Shells and Steal IIS Machine Keys

Microsoft SharePoint Server flaws are being actively exploited to deploy web shells, steal IIS machine keys, and maintain long-term access to compromised enterprise environments. The attacks affect on

CS
CyberShield Team
2026-07-20
Share:
Actively Exploited SharePoint Flaws Let Hackers Deploy Web Shells and Steal IIS Machine Keys

Microsoft SharePoint Server flaws are being actively exploited to deploy web shells, steal IIS machine keys, and maintain long-term access to compromised enterprise environments. The attacks affect on-premises SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. SharePoint Online and Microsoft 365 are not affected. CISA has added CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 to […] The post Actively Exploited SharePoint Flaws Let Hackers Deploy Web Shells and Steal IIS Machine Keys appeared first on Cyber Security News.

Microsoft SharePoint Server flaws are being actively exploited to deploy web shells, steal IIS machine keys, and maintain long-term access to compromised enterprise environments. The attacks affect on-premises SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. SharePoint Online and Microsoft 365 are not affected. CISA has added CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 to its Known Exploited Vulnerabilities catalog after confirming exploitation in the wild. The vulnerabilities allow attackers to abuse improper input validation, unsafe deserialization, and missing authentication controls. When chained, they can provide unauthorized access, remote code execution, privilege escalation, and persistence on vulnerable SharePoint servers. Microsoft also addressed CVE-2026-55040, CVE-2026-58644, and CVE-2026-50522 in its July 2026 security updates. These flaws include a JWT authentication bypass and additional unauthenticated deserialization vulnerabilities that could enable remote code execution. Organizations should patch all six issues immediately, regardless of whether every vulnerability has been publicly observed in attacks. SharePoint Flaws Enable Webshell Attacks (Source: resecurity) SharePoint Flaws Enable Webshell Attacks Attackers are targeting exposed SharePoint web applications, particularly servers accessible from the internet. They send specially crafted requests to vulnerable SharePoint endpoints to bypass authentication or trigger unsafe deserialization. Successful exploitation can run attacker-controlled code inside the IIS worker process, w3wp.exew3wp.exew3wp.exe. After gaining code execution, threat actors can upload ASP.NET web shells to SharePoint and IIS directories. One reported filename is spinstall0.aspx, although defenders should not rely only on that indicator. Attackers may use random filenames, password-protected pages, encrypted commands, or cookie-based triggers to hide their access. Common web-shell locations include SharePoint’s TEMPLATE\LAYOUTS directory and IIS virtual-directory paths. Security teams should investigate newly created or modified .aspx, .dll, .js, and .txt files in these locations, especially when they appear alongside unusual web requests or unexpected child processes. SharePoint Flaws Enable Webshell Attacks (Source: resecurity) A major concern in these attacks is theft of IIS ASP.NET machine keys. These keys sign and encrypt application data, including ViewState and forms-authentication information. If attackers obtain the validationKey and decryptionKey values from web.config, they may forge trusted application data and preserve access even after the original SharePoint vulnerability is patched. This means patching alone may not remove an intruder. Organizations must first investigate for web shells, malicious IIS modules, altered configuration files, suspicious accounts, and unauthorized processes. Machine keys should be rotated only after responders confirm the environment is clean; otherwise, attackers may steal the replacement keys, resecurity said. The compromise of a SharePoint web front-end can create a route to more sensitive systems. SharePoint commonly connects to Active Directory, SQL Server, service accounts, content databases, and internal business applications. An attacker who gains a foothold on a SharePoint server may steal documents, access backend databases, move laterally, or deploy ransomware. Prevent critical incidents and financial loss with stronger proactive defense. Integrate a live threat feed from 15K SOCs The post Actively Exploited SharePoint Flaws Let Hackers Deploy Web Shells and Steal IIS Machine Keys appeared first on Cyber Security News.

Share:

Join the Discussion

Comments coming soon. Follow us on social media for real-time discussions.