Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
World desk4 min

How to Harden SharePoint Server Against Remote Code Execution Attacks

Reduce on-premises SharePoint Server RCE exposure with edition-aware patching, role-based firewall and configuration controls, AMSI request scanning, and applicable TLS and machine-key protections.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To reduce SharePoint Server’s exposure to remote code execution (RCE), first identify the farm’s edition, build, web applications, and server roles; then install the applicable cumulative update and complete its farm-configuration steps. After patching, restrict network access and apply role-aware configuration controls, enable and verify AMSI request scanning, and check which TLS and ASP.NET machine-key protections your edition supports. These measures are defense in depth—not a guarantee against every attack or a replacement for securing Windows Server, SQL Server, identity systems, network devices, and other software.

1. Map the farm before changing it

Start with an inventory of every SharePoint server, its role, the installed SharePoint edition and build, and the web applications reachable from outside the organization. Record the ports used by those web applications, Central Administration, and farm services. Include configured features and third-party components in the map: firewall rules and service changes that are safe for one topology may break another.

Use Microsoft’s SharePoint Server security-hardening guidance as a role-aware reference for SharePoint Server 2013, 2016, 2019, and Subscription Edition. It describes common service and port needs, but your farm configuration determines which are required.

2. Install the update for the exact edition and build

Check Microsoft’s SharePoint updates page for the update applicable to your installed edition and language. Microsoft describes SharePoint updates as cumulative, but a release identifier is not a substitute for verifying what is installed or which update applies to your farm.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a dated reference, the updates page listed SharePoint Server Subscription Edition KB 5002908, version 16.0.20326.20136, released September 8, 2026. Treat that as the release entry shown on that date—not a permanent “latest” version or a statement about other editions.

  1. Confirm the farm’s edition, build, language, topology, and update prerequisites against Microsoft’s update information.
  2. Choose an update strategy and schedule the deployment for the farm. Follow Microsoft’s software-update installation procedure, including its handling for Search and Distributed Cache servers where applicable.
  3. Monitor package installation on the servers, then perform any required post-installation configuration steps for that SharePoint version and topology. Installing the update files alone may not complete the farm update.
  4. Verify the resulting build and farm health before moving to configuration changes.

For a specific vulnerability, check the Microsoft Security Update Guide and the edition-specific SharePoint update information. Do not assume that one advisory or build identifier establishes remediation for every SharePoint RCE scenario.

3. Restrict network exposure by role

Place a firewall between farm servers and outside requests. Permit only the ports required for the web applications, configured features, and server-to-server communication in your actual topology. Microsoft’s hardening guidance recommends blocking external access to the Central Administration site’s port. Do not copy a generic port list into production rules without mapping it to your farm first.

For SQL communication, restrict which servers can connect to the database tier and review Microsoft’s separate SQL Server security guidance. SharePoint’s hardening article discusses TCP 1433 and UDP 1434 behavior, but securing SharePoint does not secure SQL Server for you.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Apply configuration controls without breaking farm roles

Review the relevant Web.config files and services on each server. Make changes in a controlled way, testing them against the farm’s roles, custom solutions, and operational requirements.

Web.config and page execution

  • Avoid enabling database page compilation or scripting through PageParserPaths.
  • Keep the SafeMode call stack and page-level trace disabled.
  • Use conservative Web Part limits.
  • Minimize SafeControls and Workflow SafeTypes to what the farm requires.
  • Enable custom errors and limit upload size to what users reasonably need.

Windows services

Do not disable a SharePoint service simply because it is not needed on every server. Microsoft identifies SharePoint Administration, Timer, Tracing, and VSS Writer among core services, with additional services required for roles such as Search, Distributed Cache, and User Code. In particular, disabling administration-related services can affect deployment and farm operations.

5. Use AMSI as an additional request defense

SharePoint’s AMSI integration lets an AMSI-capable anti-malware product inspect incoming HTTP and HTTPS requests as SharePoint begins processing them. Microsoft says this may help block malicious requests to SharePoint endpoints, including attempts against a vulnerable endpoint before an official fix is installed. AMSI complements, rather than replaces, protections against infected files being uploaded or downloaded. See Microsoft’s AMSI integration guidance for setup and operational details.

Scanning behavior depends on release. Microsoft says Subscription Edition Version 25H1 extends AMSI scanning to HTTP request bodies; the capability is included in the Standard ring starting with the September 2025 public update. The same guidance says AMSI integration became mandatory for Subscription Edition, SharePoint Server 2016, and 2019 with that public update. Verify the deployed build, update ring, anti-malware product, and operational status rather than assuming identical coverage across farms.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Forvencer Server Book, 2 Zipper Pocket, Server Books for Waitress
  • Upgraded Two Zipper Pockets: Forvencer server books feature two secure zipper pockets for better organization of coins, cash, and receipts, ensuring that everything you collect has a safe and secure place
  • Smart Storage & Quick Access: Designed with 8 multi-functional compartments, the right side includes a guest receipt pad, while the left has a money pocket, ticket pocket, and credit card slot. Two small clear pockets store bills, receipts, and other visible items. A stitched pen loop ensures you always have your favorite pen ready
  • High-quality & Easy to Clean: Crafted from high-quality PU leather with heavy-duty stitching, this server book is built to last. It resists tears, scratches, and its waterproof surface makes cleaning easy with just a damp cloth or a non-chlorine sanitizer
  • Perfect Fit for Your Apron: Measuring 5” x 8”, this compact organizer is slightly smaller than other models, making it ideal for bending or sitting while carrying in your server apron. It holds everything a waitress needs—a place for everything
  • What's Included: This server organizer comes with multiple open and zippered pockets to store money, receipts, tips, etc. Clear sleeves are perfect for keeping menus or special lists while serving. Available in a variety of colors, allowing you to express yourself even when in uniform
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

6. Check TLS and machine-key protections for your edition

Control Documented applicability What to verify
Strong TLS SharePoint Server Subscription Edition on Windows Server 2022 or later Microsoft’s strong TLS guidance says SSL bindings negotiate TLS 1.2 or higher and block lower TLS versions and SSL. Confirm the documented configuration on the applicable servers; do not extend this edition and OS guidance to other combinations without checking their own requirements.
ASP.NET machine-key encryption and rotation Subscription Edition encrypts the machineKey section of Web.config by default. Automatic rotation is available for Subscription Edition Version 25H1 and for SharePoint Server 2016 and 2019 after the September 2025 Public Update. Microsoft says machine keys protect ASP.NET view state and that the rotation timer job runs weekly by default. Check the deployed edition and update level, then verify the configuration and job behavior using Microsoft’s ASP.NET view-state security and key-management guidance.

7. Verify the whole defensive chain

After changes, confirm that the intended update and farm configuration steps completed, external access is limited to the approved web applications and ports, and required farm services remain available on the servers that need them. Verify AMSI operation with the product and SharePoint build in use, and check TLS and key controls only against their documented edition and operating-system applicability. Track host, database, identity, network, and third-party hardening separately; SharePoint-specific controls do not cover those layers.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.