Cybersecurity Jul 17, 2026Add to bookmarks

The CISA adds three SharePoint vulnerabilities to its KEV catalog - confirmed exploitation in the wild. Two other critical flaws remain on the table. What to patch, and quickly.
The American agency CISA (Cybersecurity and Infrastructure Security Agency) has issued an alert regarding three actively exploited SharePoint vulnerabilities in the wild. They join the KEV (Known Exploited Vulnerabilities) catalog, which triggers for all U.S. federal agencies the obligation to patch within 21 days (BOD 22-01 directive).
In the same bulletin, The Register notes that two additional critical vulnerabilities, not yet listed in KEV, could expand the attack surface if they were exploited in turn.
Government agencies, universities, law firms, and industrial companies remain the main historical targets of SharePoint on-prem.
SharePoint has been a favorite target since 2019 (CVE-2019-0604, still exploited today) and especially since the ToolShell wave of the summer of 2025. The pattern is stable:
The current trio fits into this continuity. This is not a spectacular bug but an operational reminder: maintaining the security conditions of an on-prem SharePoint is a full-time job, not an ancillary task.
Article produced by artificial intelligence, reviewed under human editorial control.