CVE-2026-56164
Published Jul 14, 2026
Last updated a month ago
AI description
CVE-2026-56164 is a missing authentication for critical function vulnerability found in Microsoft SharePoint Server. This flaw allows an unauthorized attacker to elevate privileges over a network. The vulnerability affects all supported on-premises SharePoint Server versions, including Subscription Edition, 2019, and 2016. It has been actively exploited in the wild as a zero-day, enabling cyber threat actors to gain unauthorized access to SharePoint Server instances and potentially engage in post-exploitation activities.
- Description
- Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
- Source
- secure@microsoft.com
- NVD status
- Undergoing Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 5.3
- Impact score
- 1.4
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Severity
- MEDIUM
Data from CISA
- Vulnerability name
- Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
- Exploit added on
- Jul 14, 2026
- Exploit action due
- Jul 17, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- secure@microsoft.com
- CWE-306
- Hype score
- Not currently trending
⚡️ August "In the Trend of VM" (#30): 4 trending vulns - ViPNet Client RCE (BDU:2026-09885), Windows Kernel EoP (CVE-2026-42980), and 2 actively exploited SharePoint flaws (CVE-2026-56164, CVE-2026-58644). #TrendVulns #ViPNet #Windows #SharePoint ➡️ https://t.co/NAraJjJJU
@leonov_av
17 Aug 2026
66 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/Ri70B2BnrO https://t.co/3ua3S2vWb7
@IT_Peurico
11 Aug 2026
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Swiss Gov hit via SharePoint vulnerabilities (CVE-2026-56164 & CVE-2026-50522) 200 user & technical accounts compromised. If technical accounts fall, privilege boundary fails. Patch now! #CyberSecurity #Vulnerability #CyberAttack #ThreatIntel #SharePoint #NetShieldTec
@NetShieldTechAI
10 Aug 2026
8 Impressions
2 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164) https://t.co/vznD7BoR0u https://t.co/6IMyD4pXK2
@dansantanna
8 Aug 2026
44 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/SNLFJANHDb https://t.co/noto7ekzQB
@TechMash365
5 Aug 2026
64 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/IdSiTFG29D https://t.co/F6d1bPKsHo
@Art_Capella
27 Jul 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft's SharePoint zero-day (CVE-2026-56164) is being actively exploited. Microsoft rated it 5.3/Moderate. NVD rated it 9.8/Critical. Attackers are chaining it with older SharePoint bugs to steal IIS machine keys. Patch based on the CVE, not the vendor's own score. #ZeroDay
@McM1Alex
26 Jul 2026
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-of-the-Day: CVE-2026-56164 SharePoint's "no password needed" privilege escalation. What it is: A missing-authentication flaw in SharePoint Server — attackers can reach a vulnerable function directly and elevate privileges over the network. No access needed. 🧵
@YourDailyCVE
26 Jul 2026
19 Impressions
1 Retweet
1 Like
0 Bookmarks
2 Replies
0 Quotes
Still seeing substantial amounts of Microsoft SharePoint unpatched instances that have been added to @CISACyber Known Exploited Vulnerability catalog last few weeks. This includes CVE-2026-50522, CVE-2026-56164, CVE-2026-58644 with 878 IPs (1585 FQDNs) unpatched on 2026-07-23 ht
@Shadowserver
24 Jul 2026
1704 Impressions
6 Retweets
15 Likes
5 Bookmarks
1 Reply
0 Quotes
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/2q9gcGN5tf https://t.co/F84M3Pwt86
@ggrubamn
22 Jul 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft tarihinin en büyük Patch Tuesday'i: 622 açık, 3 sıfır gün, 2'si zaten aktif saldırıda! Temmuz güncellemesinde CVE-2026-56164 (SharePoint), kimlik doğrulaması gerektirmeden kritik işlevlere erişim sağlayarak aktif olarak istismar ediliyor. CVE-2026-56155
@BTHaberler
22 Jul 2026
53 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/dP22TvHKXe https://t.co/hX3St5TYaX
@pcasano
21 Jul 2026
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Six CVEs hit on-prem SharePoint in July 2026, four now in CISA KEV with active exploitation confirmed. Unauthenticated RCE and auth bypass can chain from a single web request to full domain compromise. - CVE-2026-56164 (CVSS 9.8, unauthenticated auth bypass, KEV due July 17) and
@DFIR_Radar
20 Jul 2026
226 Impressions
0 Retweets
1 Like
1 Bookmark
2 Replies
0 Quotes
SharePoint CVEs FAQ: CVE-2026-56164, CVE-2026-32201, CVE-2026-45659 | Tenable® https://t.co/SRRYYVs3Jv
@endi24
19 Jul 2026
2542 Impressions
5 Retweets
23 Likes
18 Bookmarks
0 Replies
0 Quotes
【緊急】CVE-2026-56164 MicrosoftのSharePoint Serverに深刻な脆弱性|即時対応が必要 https://t.co/yfmppfD9WK #IT #Security #cybersecurity
@Teeeda_worker
19 Jul 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CISA KEV Deadlines This Week 📅 Jul 17: SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) + Code Injection (CVE-2026-15410) | Microsoft SharePoint Missing Auth (CVE-2026-56164, CVSS 9.8) 📅 Jul 18: Oracle E-Business Suite Improper Privilege Management (CVE-2026-46817,
@techepages
18 Jul 2026
76 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/denoKmLMkf https://t.co/lvM94DeVpG
@EAlexStark
17 Jul 2026
69 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
July 2026 Patch Tuesday drops 622 CVEs with three zero-days: SharePoint (CVE-2026-56164) and AD FS (CVE-2026-56155) are actively exploited and CISA KEV-listed. #DFIR_Radar https://t.co/pLY8VaBF7d
@DFIR_Radar
17 Jul 2026
189 Impressions
1 Retweet
3 Likes
1 Bookmark
2 Replies
0 Quotes
Microsoft Patch Tuesday: Rekord-breaking 622 CVEs. Zwei Zero-Days (CVE-2026-56155, CVE-2026-56164) werden aktiv ausgenutzt. Sofort patchen! #PatchTuesday #CyberSecurity https://t.co/dKB08AxiKK
@wall_your_x
17 Jul 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/Qr0dCd19Nh https://t.co/wD4LUwwYHc
@dansantanna
17 Jul 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
MS Patch Tuesday (Jul 14/15) addressed active zero-days: CVE-2026-56164 (SharePoint) & CVE-2026-56155 (ADFS) enable privilege escalation. SonicWall SMA1000 zero-days also exploited. Data integrity/privacy at risk. #Cybersecurity #InfoSec #Vulnerabilities
@YourAnon_irc
17 Jul 2026
52 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Four on-premises SharePoint Server CVEs are actively exploited: CVE-2026-32201 (CVSS 6.5), CVE-2026-45659 (CVSS 8.8), CVE-2026-56164 (CVSS 9.8), and CVE-2026-58644 (CVSS 9.8). #DFIR_Radar https://t.co/ln2QdK28Q8
@DFIR_Radar
17 Jul 2026
190 Impressions
0 Retweets
1 Like
1 Bookmark
2 Replies
0 Quotes
🛡️ Microsoft's July Patch Tuesday: 622 CVEs, the largest on record. Two under active attack — CVE-2026-56164 (SharePoint) and CVE-2026-56155 (AD FS). What's exploitable and what to patch first: https://t.co/YdTCg7eWT0
@colibrisec
16 Jul 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Exploitation Warnings for SharePoint Server Demand Immediate Action https://t.co/uVEGqZq5Sn #CVE2026 #SharePoint #CyberSecurity
@cyber_newsroom
16 Jul 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Microsoft July 2026 Patch Tuesday: 622 flaws fixed. 2 zero-days exploited. 🔴 CVE-2026-56164 — SharePoint 🔴 CVE-2026-56155 — AD FS Patch exploited identity and collaboration systems first. Don’t rely on CVSS alone. https://t.co/dGByZy5j04 #CyberSecurity #PatchTues
@vulert_official
16 Jul 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft ships its biggest Patch Tuesday ever with 2 zero-days already exploited: AD FS (CVE-2026-56155) + SharePoint (CVE-2026-56164). Plus a 4th BitLocker bypass in 5 weeks (CVE-2026-50661). Patch now. https://t.co/qs2aI4iwIR https://t.co/opbzEJk06M #CyberSecurity http
@DIESEC_GmbH
16 Jul 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔎 V rámci červencového Patch Tuesday bylo opraveno rekordních 622 zranitelností. Dvě zero day chyby umožňující zvýšení oprávnění již byly aktivně zneužívány: ⚠️ CVE-2026-56164 v on-premises SharePoint Serveru ⚠️ CVE-2026-56155 v ADFS Třetí zero
@sec4good
16 Jul 2026
60 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164) https://t.co/dF0u4oO0St https://t.co/2Nnvf2s9pc
@ggrubamn
15 Jul 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft just shipped 622 CVE patches — biggest release in company history — and 2 are already exploited. If you're on Windows and haven't updated this week, your machine is a soft target for CVE-2026-56164 (SharePoint) + CVE-2026-56155 (AD FS). Update tonight.
@FaultSignal_
15 Jul 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-58644: SharePoint Server deserialization RCE (CVSS 9.8). Unauthenticated, network-exploitable. Sibling CVE demoed at Pwn2Own Berlin. Same July 14 patches as KEV-listed CVE-2026-56164. Investigation workflow → https://t.co/XV8bU4m3Ph
@hellorecon
15 Jul 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164) https://t.co/RIwE8jAnDX https://t.co/72juYIrOoL
@secured_cyber
15 Jul 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
These security flaws (tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) affect all supported self-hosted SharePoint Server versions. https://t.co/q9ukzEgfYf
@jbhall56
15 Jul 2026
60 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Running SharePoint? There are at least 4 vulns you want to pay attention to: CVE-2026-55040, CVE-2026-52522, CVE-2026-58644, CVE-2026-56164 unauthenticated RCE, exploits available etc. https://t.co/9moTd0gNju
@theluemmel
15 Jul 2026
2063 Impressions
2 Retweets
16 Likes
8 Bookmarks
2 Replies
0 Quotes
🚨 CISA deadline alert: 3 actively exploited flaws must be patched by July 17 🔹 CVE-2026-15409: SonicWall SMA1000 SSRF — unauthenticated remote exploitation 🔹 CVE-2026-15410: SonicWall SMA1000 code injection enables admin OS commands 🔹 CVE-2026-56164: SharePoint mis
@techepages
15 Jul 2026
70 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Microsoft patches 3 zero-days in July 2026 Patch Tuesday — 2 already under attack 🚨 🔹 CVE-2026-56155: AD FS flaw grants admin privileges, exploited in the wild 🔹 CVE-2026-56164: SharePoint bug lets remote attackers elevate privileges 🔹 CVE-2026-50661: BitLocker byp
@techepages
15 Jul 2026
60 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: SharePoint Server Active Exploi… "On July 14, 2026, CISA issued an urgent alert regarding active exploitation of…" 🔗 https://t.co/A0C48eSEX9 #CyberSecurity #ThreatIntel #managedsoc #mdr #securitymonito
@SecurityAr58409
15 Jul 2026
59 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-56164: Microsoft SharePoint Server Exploitation — Detection and Remedi… "On July 14, 2026, CISA added CVE-2026-56164, affecting Microsoft SharePoint Server,…" 🔗 https://t.co/C2fuYYWcEe #CyberSecurity #ThreatIntel #cve202656164 #critical #
@SecurityAr58409
15 Jul 2026
37 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA warns SharePoint vulnerabilities CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 are exploited in the wild. Patch and harden servers now. #CISA #SharePoint #Microsoft #CVE #CyberSecurity https://t.co/SN49kOAPnL
@Daily_CyberSec
15 Jul 2026
375 Impressions
1 Retweet
2 Likes
0 Bookmarks
1 Reply
0 Quotes
【脆弱性の嵐】マイクロソフトさん、月例更新で史上最多となる622件の脆弱性を修正。ゼロデイはADFSのCVE-2026-56155とSharePointのCVE-2026-56164の2件。他外部指摘は物理でのBitLocker回避CVE-2026-50661。 https://t.co/zJK92NBTQE
@__kokumoto
14 Jul 2026
1910 Impressions
4 Retweets
15 Likes
3 Bookmarks
1 Reply
1 Quote
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。月次更新関連。SonicWall SMA1000のCVE-2026-15409とCVE-2026-15410、ADFSのCVE-2026-56155、SharePointのCVE-2026-56164。
@__kokumoto
14 Jul 2026
2150 Impressions
0 Retweets
3 Likes
0 Bookmarks
1 Reply
1 Quote
Microsoft's July 2026 Patch Tuesday fixes 570 flaws. Zero-days CVE-2026-56155 and CVE-2026-56164 are exploited in the wild. Patch now. #PatchTuesday #Microsoft #ZeroDay #CVE #CyberSecurity https://t.co/cdi7Tiqj27
@Daily_CyberSec
14 Jul 2026
339 Impressions
3 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Microsoft Patch Tuesday (July 2026): Microsoft has patched ~570 vulnerabilities, including critical RCE flaws and three publicly disclosed issues: CVE-2026-56164, CVE-2026-56155, and CVE-2026-50661. #CyberSecurity #Microsoft #PatchTuesday #CVE #ThreatWire
@ThreatWire_
14 Jul 2026
75 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Microsoft’s July 2026 Patch Tuesday delivers fixes for approximately 570 vulnerabilities across its product ecosystem, following June’s record-breaking release of 206 flaws that also included three publicly disclosed zero-days. 📌 CVE-2026-56164 📌 CVE-2026-56155 📌 ht
@The_Cyber_News
14 Jul 2026
7760 Impressions
33 Retweets
130 Likes
27 Bookmarks
5 Replies
0 Quotes