July 21, 2026

CISA issues Microsoft SharePoint cybersecurity alert

By: Joe Paone
Share

The U.S. Cybersecurity and Infrastructure Security Agency has issued an alert about four vulnerabilities in Microsoft SharePoint, the widely-used cloud-based collaboration and document management platform included with Microsoft 365, that are being exploited by cyber threat actors to “establish remote code execution and perform other actions to deploy malware,” according to a statement from the American Hospital Association (AHA).

The CISA alert “urges SharePoint hardening after new exploitations.”

The vulnerabilities affect all supported on-premises versions of SharePoint Server, including the Subscription Edition, 2019 and 2016. CISA recommends that organizations monitor SharePoint Servers closely for any signs of exploitation or unusual activity, and apply Microsoft’s latest patches and security updates. Read CISA’s full alert here.

“Hospitals with their SharePoint instances housed on premises should pay particular attention to this alert,” stated Scott Gee, AHA’s deputy national advisor for cybersecurity and risk.

Join our community

Learn More
Video Spotlight
Live chat by BoldChat