SharePoint Server zero-day actively exploited: CISA warns of IIS key theft to survive patches

Cybersecurity Aug 25, 2026Add to bookmarks

SharePoint Server zero-day actively exploited: CISA warns of IIS key theft to survive patches
Illustration : Momiji Shirogane

Attackers are actively exploiting vulnerabilities in on-premises SharePoint Server to gain Farm Administrator rights and steal IIS machine keys to maintain access even after applying a patch.

What's happening

The CISA (Cybersecurity and Infrastructure Security Agency) has issued an alert about active exploitation of vulnerabilities in SharePoint Server on-premises—local installations, not SharePoint Online (Microsoft 365). Attackers are targeting CVEs that allow them to obtain Farm Administrator rights, the highest level of access on a SharePoint farm.

A documented feature of this campaign: attackers steal IIS (Internet Information Services) machine keys to ensure persistence. These keys allow them to decrypt Windows authentication tokens and forge new valid tokens—which means the attacker can survive patch application if the keys are not regenerated after remediation.

Who is impacted

SharePoint Server on-premises only. At risk are large enterprises, government agencies, and institutions that maintain their own SharePoint farms without migrating to Microsoft 365.

Facts vs. analysis

Facts:

  • Active exploitation confirmed by CISA
  • Vector: CVEs targeting escalation to Farm Admin on SharePoint on-premises
  • Documented persistence technique: theft of IIS machine keys

Analysis: The technique of stealing IIS keys is particularly insidious. Applying the patch is not enough to evict an attacker who has already stolen them: they can continue forging valid tokens as long as the keys are not regenerated. This persistence can remain active for weeks after remediation if this step is overlooked.

What to do now

1. Apply the CVEs patches mentioned in the CISA advisory to your SharePoint on-premises servers\n2. Regenerate IIS machine keys AFTER patching—this mandatory step is often forgotten\n3. Audit SharePoint logs for abnormal Farm Admin connections\n4. Reassess on-premises maintenance: each month without migration increases the attack surface

Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

SSHSelf-hostedAI Ops
Get early access
Was this article helpful?

4 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

Get early access
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information