CISA sounds alarm over trio of exploited SharePoint flaws 59%

7/15/2026, 8:21:58 AM

BS Summary: This article contains 15 faulty reasoning types, including Negativity Bias, Appeal to Authority, and Framing Effect, with Indoctrination as the most egregious example at 36.2% saturation with 147 hits. Analysis detected 725 faulty-reasoning hits from 406 analyzed words, generating a BS Score of 55.2% and a BS Rank of 59% (9,101 of 21,887 articles). This article is worse (more manipulative) than 58.40% of the article peer group.

The US Cybersecurity and Infrastructure Security Agency (CISA) has urged all organizations running SharePoint to harden their defenses after the disclosure of actively exploited vulnerabilities. 
The warning applies to those running any supported version of SharePoint Server on-prem, with three vulnerabilities of particular interest cited. 
A spoofing bug, CVE-2026-32201 (6.5), was the first to be mentioned. 
Microsoft disclosed it in March and CISA confirmed it was being actively exploited in June. 
Additionally, CISA appears concerned by CVE-2026-45659 (8.8)  a remote code execution (RCE) flaw made public in June and confirmed as being actively used in attacks last week after Microsoft said exploitation was "less likely." 
The most recent of the three, CVE-2026-56164 (5.3), a privilege escalation flaw, was one of the 622 bugs that featured in this month's record Patch Tuesday. 
CISA also picked out two more critical bugs, both from the latest Patch Tuesday, as ones that could potentially complicate SharePoint security further. 
Neither CVE-2026-55040 (9.1) nor CVE-2026-58644 (9.8) is being actively exploited to date, although Microsoft has attached the "Exploitation More Likely" label to both. 
CISA said the three exploited vulnerabilities are associated with post-exploitation activity, including the theft of Internet Information Services (IIS) machine keys and deserialization techniques, both in an effort to gain persistence and deploy malware. 
The agency did not offer any more detail about what led it to issue the warning, but went on to encourage defenders to review an alert it published in August 2025, which similarly urged organizations to harden SharePoint from "ToolShell" attacks. 
CISA said attackers were chaining together CVE-2025-49706 (6.5) and CVE-2025-49704 (8.8) to break into SharePoint Servers and, in some cases, deploy Warlock ransomware. 
It did not go as far as attributing the activity referenced in either SharePoint advisory to any group or country, although Microsoft said as far back as July 2025 that ToolShell vulnerabilities were being exploited by Chinese nation-state crews. 
Applying Microsoft's latest security patches and verifying that Antimalware Scan Interface (AMSI) integration is enabled for each SharePoint web application are among the recommended hardening measures. 
CISA also advised defenders to go threat hunting for signs of intrusion before rotating IIS keys to avoid exposing SharePoint to the web unless it's necessary and block external access to SharePoint Central Administration. 
As is the case with any potential intrusion, CISA encouraged organizations to implement robust, tailored logging that can detect potential exploits. 
® 
Article reasoning-pattern comparisonThis article: 0.0%The Register: 3.3%Confirmation Bias0.0%This article: 0.0%The Register: 1.0%Anchoring Bias0.0%This article: 14.8%The Register: 3.2%Availability Heuristic14.8%This article: 0.0%The Register: 1.1%Representativeness Heuristic0.0%This article: 0.0%The Register: 1.3%Hindsight Bias0.0%This article: 0.0%The Register: 2.3%Overconfidence Bias0.0%This article: 15.8%The Register: 5.0%Framing Effect15.8%This article: 0.0%The Register: 0.7%Loss Aversion0.0%This article: 8.4%The Register: 0.8%Status Quo Bias8.4%This article: 0.0%The Register: 0.2%Sunk Cost Effect0.0%This article: 5.7%The Register: 3.0%Optimism Bias5.7%This article: 0.0%The Register: 2.6%Pessimism Bias0.0%This article: 22.2%The Register: 8.2%Negativity Bias22.2%This article: 0.0%The Register: 1.9%Self-Serving Bias0.0%This article: 0.0%The Register: 0.8%Fundamental Attribution Error0.0%This article: 0.0%The Register: 0.1%Actor-Observer Bias0.0%This article: 0.0%The Register: 0.4%In-Group Bias0.0%This article: 9.6%The Register: 0.4%Out-Group Homogeneity Bias9.6%This article: 0.0%The Register: 1.4%Halo Effect0.0%This article: 0.0%The Register: 0.1%Horn Effect0.0%This article: 0.0%The Register: 0.0%Dunning-Kruger Effect0.0%This article: 10.1%The Register: 1.9%Recency Bias10.1%This article: 2.7%The Register: 0.3%Primacy Effect2.7%This article: 0.0%The Register: 0.1%Blind-Spot Bias0.0%This article: 0.0%The Register: 0.7%Ad Hominem0.0%This article: 0.0%The Register: 0.2%Straw Man0.0%This article: 16.3%The Register: 4.2%Appeal to Authority16.3%This article: 5.7%The Register: 1.7%False Dilemma5.7%This article: 0.0%The Register: 1.2%Slippery Slope0.0%This article: 0.0%The Register: 0.1%Circular Reasoning0.0%This article: 0.0%The Register: 6.2%Hasty Generalization0.0%This article: 0.0%The Register: 0.3%Red Herring0.0%This article: 0.0%The Register: 0.7%Bandwagon0.0%This article: 0.0%The Register: 3.0%Appeal to Emotion0.0%This article: 0.0%The Register: 0.9%Begging the Question0.0%This article: 8.6%The Register: 2.0%Post Hoc (False Cause)8.6%This article: 0.0%The Register: 0.2%Tu Quoque0.0%This article: 0.0%The Register: 0.7%Burden of Proof0.0%This article: 0.0%The Register: 0.2%Appeal to Nature0.0%This article: 5.2%The Register: 0.3%Composition/Division5.2%This article: 0.0%The Register: 2.2%Anecdotal0.0%This article: 0.0%The Register: 0.0%No True Scotsman0.0%This article: 15.3%The Register: 2.1%Ambiguity (Equivocation)15.3%This article: 0.0%The Register: 0.0%Gambler’s Fallacy0.0%This article: 0.0%The Register: 0.1%Middle Ground0.0%This article: 0.0%The Register: 0.1%Personal Incredulity0.0%This article: 0.0%The Register: 0.2%Special Pleading0.0%This article: 0.0%The Register: 0.2%Genetic Fallacy0.0%This article: 0.0%The Register: 2.3%Unattributed Quote0.0%This article: 0.0%The Register: 1.3%Quote-first Misdirection0.0%This article: 2.2%The Register: 7.3%Biased Writer Voice2.2%This article: 36.2%The Register: 1.5%Indoctrination36.2%This article: 0.0%The Register: 0.2%Politically Left Leaning Bias0.0%This article: 0.0%The Register: 0.1%Politically Right Leaning Bias0.0%This article: 0.0%The Register: 2.5%Attempt to Sell a Product or S…0.0%

406 words analyzed.

Speakers

2speakers73%attributed speech111writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 9 words • 100.0% coverageCISA • 25 words • 100.0% coverageCISA • 20 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageCISA • 35 words • 0.0% coverageWriter's voice • 26 words • 0.0% coverageCISA • 23 words • 0.0% coverageWriter's voice • 23 words • 0.0% coverageCISA • 34 words • 0.0% coverageCISA • 41 words • 100.0% coverageCISA • 23 words • 0.0% coverageMicrosoft • 39 words • 0.0% coverageWriter's voice • 26 words • 100.0% coverageCISA • 34 words • 100.0% coverageCISA • 21 words • 100.0% coverageWriter's voice • 1 words • 0.0% coverage
Selected voice

Microsoft

100%flagged-word coverage
39 attributed words13% of attributed speech99% writer coverage
0%12.5%25.0%Indoctrination-23.4 ptsWriter: 23.4%Microsoft: 0.0%0.0%Biased Writer Voice-8.1 ptsWriter: 8.1%Microsoft: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.