ALMC
ALMC Security Logo - Mantenimiento Web, Programación Web Barcelona, Servidores Barcelona, Ciberseguridad Barcelona
  • English
    Español English Français Català

Quick search

Results without leaving the page.

Type to search ALMC products, services, articles and tools.

View all results
Habla a nuestro AgenteIA · respuestas al instante · 24/7
  • HomeALMC
  • ALMCAbout Us
  • ALMC SECURITY S.L.U.Contact
  • Posts
    • Posts
    • Categorías
    • Etiquetas
    • Estados
  • Soluciones
    • Desarrollo Web en Lleida — Diseño a Medida que Vende
    • Tienda Online a Medida — E-commerce que Vende de Verdad
    • Chatbot IA para Empresas — Automatiza tu Atención al Cliente
    • Automatización de Procesos para Empresas — Menos Tareas, Más Resultados
    • Desarrollo de Apps Móviles — iOS y Android a Medida
  • Services
    • Cybersecurity
      • Security Audits and Pentesting
      • Monitoring & Incident Response (SIEM)
      • System & Server Hardening
      • Compliance Consulting (GDPR, ENS, ISO 27001)
      • Cloud Security (AWS, Azure, Google Cloud)
    • Programming
      • Full Stack Web Development Laravel, Vue.js
      • Process Automation (Scripts and Bots)
      • Process Automation Scripts and Bots
      • API Integrations & Microservices
      • Code Maintenance and Optimization
    • Servers
      • Server Management & Monitoring
      • Cloud Migration (AWS, Azure, Google Cloud)
      • Performance Optimization
      • Virtualization & Containers (Docker, Kubernetes)
      • Backup & Disaster Recovery Plans
    • Repair Hacked Website
    • Website Maintenance
      • WordPress Maintenance
      • PrestaShop Maintenance
      • Magento Maintenance
      • Joomla Maintenance
      • Drupal Maintenance
      • Shopify Maintenance
      • Wix Maintenance
      • Concrete5 Maintenance
      • HTML Maintenance
      • PHP Maintenance
      • JavaScript Maintenance
      • Python Maintenance
    • Website Repair
      • Hacked site cleanup
      • Fix WordPress
      • Fix PrestaShop
      • Fix Magento
      • Fix Joomla
      • Fix Drupal
      • Fix Shopify
      • Fix OpenCart
      • Fix Moodle
  • Industries
    • 3D Printing & Additive
    • Accounting
    • Advertising & Marketing
    • Aerospace & Defense
    • Agriculture
    • Architecture & Engineering
    • Arts & Culture
    • Automotive
    • Banking & Finance
    • Biomedical Research
    • Biotechnology
    • Breweries
    • Call Centers & BPO
    • Chemicals
    • Cleaning Services
    • Clinics
    • Cloud Providers
    • Construction
    • Consulting
    • Cosmetics & Beauty
    • Courier & Last Mile
    • Cybersecurity
    • Data Centers
    • Defense & Security
    • E-Commerce
    • EdTech
    • Education (K-12)
    • Electrical Equipment
    • Electronics
    • Environmental NGOs
    • Environmental Services
    • Events & Conferences
    • Facilities Management
    • Fashion & Luxury
    • FinTech
    • Fishing & Aquaculture
    • Food & Beverage Manufacturing
    • Forestry
    • Freight Transport
    • Furniture
    • Gaming
    • Government & Public Administration
    • GovTech
    • Gyms & Fitness Centers
    • Healthcare Providers
    • HealthTech
    • Higher Education
    • Home Appliances
    • Home Services
    • Hospitality
    • Hospitals
    • Human Resources
    • Insurance
    • InsurTech
    • Internet & Web Services
    • Investment & Asset Management
    • IT Services
    • Jewelry
    • Landscaping & Gardening
    • Legal Services
    • Logistics & Supply Chain
    • Machinery
    • Maritime
    • Media & Entertainment
    • Medical Devices
    • Metals
    • Mining
    • Music Industry
    • Nonprofit & NGOs
    • Oil & Gas
    • Paper & Print Media
    • Paper & Pulp
    • Pharmaceuticals
    • Photography & Video
    • Plastics
    • Postal & Courier
    • Printing
    • Private Education & Academies
    • Property Development
    • Property Management
    • PropTech
    • Public Safety & Emergency
    • Publishing
    • Rail & Public Transport
    • Real Estate
    • Real Estate Agencies
    • Religious Organizations
    • Renewable Energy
    • Research & Development
    • Research Labs
    • Restaurants & Food Service
    • Retail
    • Security Services
    • Semiconductors
    • Software Development
    • Sports & Fitness
    • Sports Clubs
    • Staffing & Recruitment
    • Telecommunications
    • Textile & Apparel
    • Tobacco
    • Toys
    • Travel & Tourism
    • Travel Agencies
    • Utilities
    • Veterinary & Animal Care
    • Warehousing
    • Waste Management
    • Water Treatment
    • Wholesale
    • Wineries & Vineyards
  • Tools
    • Network
      • What's my IP
      • WHOIS IP
      • Domain WHOIS
      • Geolocate IP
      • DNS Lookup
      • DNS Propagation
      • ASN Lookup
      • Reverse Lookup
      • Domain monitoring
    • Image Compressor
    • MCP Servers
  • Products
    • Whatsboost
      • Whatsboost PrestaShop
      • Whatsboost WordPress
      • Whatsboost Shopify
    • Ulix
      • Extension QR para navegador
    • Chatbot
      • Chatbot WhatsApp
      • Chatbot Instagram
      • Chatbot Facebook
      • Chatbot TikTok
    • VeriFactu
    • Web TV
      • Mis pantallas
      • Vincular nueva TV
      • Dispositivos vinculados
      • Releases APK
      • Pantallas por cliente
    • Control de Fichajes

5 News at ALMC
  • Inauguration of the... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Inauguration of the...It was a very busy and special day. 30 Jun 2025
  • Website Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    WebsiteI recover the domain I had in the past and set up... 01 Jun 2025
  • Signing of the Lease... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Signing of the Lease...After spending some time looking for premises, my... 01 Jun 2025
  • ALMC returns and com... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    ALMC returns and com...We reactivate the brand with ALMC SECURITY SL (CIF... 23 Apr 2025
  • feb. 2025 Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    feb. 2025The decision to start entrepreneurship again was b... 01 Feb 2025

View all news

CISA Warns: Actively Exploited SharePoint RCE Vulnerability

  1. Home
  2. Blog
  3. Categories
  4. Cybersecurity
  5. CISA Warns: Actively Exploited SharePoint RCE...
  • All articles
  • Categories
  • Tags
  • Statuses

CISA Warns: Actively Exploited SharePoint RCE Vulnerability

Urgent Action Required: Actively Exploited SharePoint VulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026...

Urgent Action Required: Actively Exploited SharePoint Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-45659 to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in the wild. This critical remote code execution (RCE) flaw affects Microsoft SharePoint Server and demands immediate attention from system administrators, hosting companies, and any organisation running SharePoint on-premises.

Padlock on a server rack with a crack leaking binary code

Understanding the Threat

The vulnerability stems from insecure deserialization of untrusted data, a class of flaw particularly dangerous in corporate environments as it can allow an attacker to execute arbitrary code on the server. While exploitation requires authentication, it does not require elevated privileges – a standard account with minimal permissions, similar to a site member role, is sufficient. The attack complexity is low and no user interaction is needed, making it an attractive target for automated attacks, especially if the SharePoint instance is exposed to the internet.

Microsoft's Response and Documentation Oversight

Microsoft released security updates on 21 May 2026 for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. However, the company acknowledged a documentation error: CVE-2026-45659 was not initially listed in that patch cycle. Environments that have fully applied the May updates should be protected, but administrators must verify the patch level to ensure coverage.

Scope of Exposure

Public telemetry suggests more than 10,000 SharePoint servers are exposed to the internet, although this figure does not indicate how many are patched. The risk is amplified for organisations that have not yet applied the updates, as attackers are actively scanning for vulnerable instances.

Remediation Deadlines and Best Practices

CISA has set a remediation deadline of 4 July 2026 for federal agencies under Binding Operational Directive (BOD) 26-04, a clear signal of operational priority when active exploitation is confirmed. For all organisations, the response should involve three key actions:

  • Apply Patches Immediately: Install the May 2026 security updates or later versions on all SharePoint farms. Verify that the patches are correctly deployed, as the documentation oversight may lead to oversight.
  • Inventory and Reduce Exposure: Identify all SharePoint instances, assess their internet-facing exposure, and implement network segmentation and access controls. If a server does not need to be publicly accessible, restrict access to trusted networks.
  • Monitor and Respond: Review logs and telemetry for signs of compromise. Activate incident response procedures if any suspicious activity is detected. Treat any instance not updated before 21 May 2026 as high-risk and accelerate containment and integrity checks.

No Confirmed Campaigns Yet

As of now, no specific campaigns, threat actors, or indicators of compromise have been publicly disclosed. This makes it even more critical to assume that any unpatched SharePoint server could be at risk and to act swiftly.

Protecting Your Infrastructure

Beyond patching, a robust security posture includes proactive measures such as centralised threat intelligence and automated IP blocking. At ALMC.es, we help businesses in Lleida, Barcelona, Tarragona, and Girona strengthen their server security. Our Abuse Shield service centralises protection across your servers, automatically blocking malicious IPs, managing fail2ban across multiple machines, and sharing a reputation feed among all your systems. This layered approach helps mitigate risks from vulnerabilities like CVE-2026-45659 and reduces the attack surface.

Don't wait for an incident to occur. Review your SharePoint deployment today, apply the necessary patches, and consider enhancing your security infrastructure with proactive threat management. Contact ALMC.es to learn how we can help secure your servers and protect your business data.

Related

  • GhostLock CVE-2026-43499: Patch Your Linux Servers Now
  • RoguePlanet: Microsoft Patches Defender Zero-Day, Update Now
  • NPM Supply Chain Attack: How a Malicious SDK Compromised Crypto Wallets
  • Desarrollo web

Put these ideas into practice

Talk to ALMC about a solution for your business. Explore your options or contact our team.

Soluciones ALMC

API Integrations & Microservices
Full Stack Web Development Laravel, Vue.js
Compliance Consulting (GDPR, ENS, ISO 27001)
Cloud Migration (AWS, Azure, Google Cloud)
Cloud Security (AWS, Azure, Google Cloud)
Relacionados
  • Critical LoadMaster RCE: What Sysadmins Must Do Now
    Cybersecurity · 1 hour ago
  • Opera GX Patch: Guarding Against Malicious Browser Mods
    Cybersecurity · 1 hour ago
  • Azure CLI Password Spraying: Lessons for Server Security
    Cybersecurity · 1 hour ago
  • SonicWall SMA1000 Zero-Days: Urgent Patch Guidance for SysAdmins
    Cybersecurity · 2 hours ago
  • UEFI Secure Boot Bypass: Why Old Shims Threaten Your Servers
    Cybersecurity · 2 hours ago
  • Evilginx and Device Code Phishing: Lessons from a Misconfigured Server
    Cybersecurity · 2 hours ago
Servidores MCP Destacados
  • NCBI Literature Search
    Search
  • Finviz MCP Server
    Search
  • Email sending MCP
    Communication
  • Ares DevOps
    Version Control
  • JVM MCP Server
    Development
  • Agentcy
    Productivity
  • Rember
    Productivity
  • Iron Manus MCP
    Productivity
  • GAM MCP Server
    Cloud Service
Ver todos los servidores MCP
Cybersecurity · Blog Brain · 2026-09-08
Cerrar panel
Your ecosystem

SaaS applications

Open each workspace directly with your ALMC account.

My account Create account
VeriFactuVerified invoicingAbuse ShieldWeb securityWhatsBoostSales and CRMCommerceStore and POSEmail AISmart emailWebTVDigital signageTime trackingWorking-time controlPrintFlowPrint workflows
Agente Smith · ALMCAgente IA propio on-premise

Hola 👋 Soy Smith, el agente IA de ALMC. Pregúntame sobre ciberseguridad, IA, desarrollo a medida o nuestros productos SaaS.

¿Prefieres hablar con persona? Contacto humano

ALMC access centre

One account · All your services

Start wherever you want.

Create an account to centralise your services, or ask for guidance if you do not know what you need yet.

Create account Talk to ALMC

Explore by product

VeriFactuInvoicingAbuse ShieldSecurityWhatsBoostSalesCommerceStore and POSEmail AIAutomationWebTVDigital signage

Sign in to your account.

The same sign-in brings together your services, team and billing.

Enter my panelAccess your services, team and billing.
Sign in

Not a client yet? Create an account

ALMC Security Logo

Experts in cybersecurity, custom Laravel development, and server management. We deliver robust, secure, and personalized technological solutions.

Latest News

Inauguration of the first office in Lleida of ALMC SECURITY SL
Inauguration of the first office in Lleida of ALMC...
30 Jun 2025
Website
01 Jun 2025
Signing of the Lease Contract
Signing of the Lease Contract
01 Jun 2025

Main Services

  • desarrollo web lleida
  • tienda online a medida
  • chatbot ia empresa
  • automatización procesos empresa
  • desarrollo aplicaciones móviles

Suite SaaS

  • PrintFlow (copisterías)
  • WebTV (cartelería)
  • VeriFactu (facturación)
  • Fichaje horario

Contact

  • Rambla de Ferran, 37, 25007 Lleida

  • +34 614 443 757

  • info@almc.es

Follow Us

Useful links

  • About us
  • Contact
  • Reserva cita
  • Hacked website repair
  • Website maintenance
  • Website repair
  • Tools
  • What is my IP
  • Compress images
  • Site search
  • Blog

© Copyright 2026. ALMC SECURITY S.L.U.

  • Legal
      • Privacy Policy
      • Terms and Conditions of Service
      • Legal Notice and Corporate Information
      • Cookie Policy
  • Resources
    • Blog
    • Sitemap

ALMC

Legal

This site only uses first-party cookies and local browser storage, and only to make it work: keeping your session, protecting forms, remembering your language and not showing you this notice again. We use no analytics or advertising cookies, there are no third-party cookies and we do not build profiles. As strictly necessary technical cookies, they are exempt from consent under Article 22.2 of the Spanish LSSI-CE: this notice is informative and the button only stops it from appearing again. You can delete or block them from your browser, though some features may then stop working. Cookie Policy · Privacy Policy.

Chat now
Call Sales
+34 614 443 757

More ways to contact us

¿Hablamos directamente?

Reserva una cita en mi agenda — yo te llamo o nos vemos por Google Meet

  • ✓Confirmación instantánea por WhatsApp
  • ✓Disponibilidad en tiempo real
  • ✓Recordatorio 1h antes
  • ✓Cancela o cambia hora con un click
Initial consultation · 30min
📅 Ver disponibilidad y reservar