CVE-2026-56164

Published Jul 14, 2026

Last updated a month ago

Exploit knownCVSS medium 5.3
lms
Cloud
Network
Zero-day
Server

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-56164 is a missing authentication for critical function vulnerability found in Microsoft SharePoint Server. This flaw allows an unauthorized attacker to elevate privileges over a network. The vulnerability affects all supported on-premises SharePoint Server versions, including Subscription Edition, 2019, and 2016. It has been actively exploited in the wild as a zero-day, enabling cyber threat actors to gain unauthorized access to SharePoint Server instances and potentially engage in post-exploitation activities.

Description
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
Source
secure@microsoft.com
NVD status
Undergoing Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
5.3
Impact score
1.4
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Severity
MEDIUM

Known exploits

Data from CISA

Vulnerability name
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
Exploit added on
Jul 14, 2026
Exploit action due
Jul 17, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

secure@microsoft.com
CWE-306

Social media

Hype score
Not currently trending
  1. ⚡️ August "In the Trend of VM" (#30): 4 trending vulns - ViPNet Client RCE (BDU:2026-09885), Windows Kernel EoP (CVE-2026-42980), and 2 actively exploited SharePoint flaws (CVE-2026-56164, CVE-2026-58644). #TrendVulns #ViPNet #Windows #SharePoint ➡️ https://t.co/NAraJjJJU

    @leonov_av

    17 Aug 2026

    66 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/Ri70B2BnrO https://t.co/3ua3S2vWb7

    @IT_Peurico

    11 Aug 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Swiss Gov hit via SharePoint vulnerabilities (CVE-2026-56164 & CVE-2026-50522) 200 user & technical accounts compromised. If technical accounts fall, privilege boundary fails. Patch now! #CyberSecurity #Vulnerability #CyberAttack #ThreatIntel #SharePoint #NetShieldTec

    @NetShieldTechAI

    10 Aug 2026

    8 Impressions

    2 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164) https://t.co/vznD7BoR0u https://t.co/6IMyD4pXK2

    @dansantanna

    8 Aug 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/SNLFJANHDb https://t.co/noto7ekzQB

    @TechMash365

    5 Aug 2026

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/IdSiTFG29D https://t.co/F6d1bPKsHo

    @Art_Capella

    27 Jul 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Microsoft's SharePoint zero-day (CVE-2026-56164) is being actively exploited. Microsoft rated it 5.3/Moderate. NVD rated it 9.8/Critical. Attackers are chaining it with older SharePoint bugs to steal IIS machine keys. Patch based on the CVE, not the vendor's own score. #ZeroDay

    @McM1Alex

    26 Jul 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 CVE-of-the-Day: CVE-2026-56164 SharePoint's "no password needed" privilege escalation. What it is: A missing-authentication flaw in SharePoint Server — attackers can reach a vulnerable function directly and elevate privileges over the network. No access needed. 🧵

    @YourDailyCVE

    26 Jul 2026

    19 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    2 Replies

    0 Quotes

  9. Still seeing substantial amounts of Microsoft SharePoint unpatched instances that have been added to @CISACyber Known Exploited Vulnerability catalog last few weeks. This includes CVE-2026-50522, CVE-2026-56164, CVE-2026-58644 with 878 IPs (1585 FQDNs) unpatched on 2026-07-23 ht

    @Shadowserver

    24 Jul 2026

    1704 Impressions

    6 Retweets

    15 Likes

    5 Bookmarks

    1 Reply

    0 Quotes

  10. CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/2q9gcGN5tf https://t.co/F84M3Pwt86

    @ggrubamn

    22 Jul 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Microsoft tarihinin en büyük Patch Tuesday'i: 622 açık, 3 sıfır gün, 2'si zaten aktif saldırıda! Temmuz güncellemesinde CVE-2026-56164 (SharePoint), kimlik doğrulaması gerektirmeden kritik işlevlere erişim sağlayarak aktif olarak istismar ediliyor. CVE-2026-56155

    @BTHaberler

    22 Jul 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/dP22TvHKXe https://t.co/hX3St5TYaX

    @pcasano

    21 Jul 2026

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Six CVEs hit on-prem SharePoint in July 2026, four now in CISA KEV with active exploitation confirmed. Unauthenticated RCE and auth bypass can chain from a single web request to full domain compromise. - CVE-2026-56164 (CVSS 9.8, unauthenticated auth bypass, KEV due July 17) and

    @DFIR_Radar

    20 Jul 2026

    226 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    2 Replies

    0 Quotes

  14. SharePoint CVEs FAQ: CVE-2026-56164, CVE-2026-32201, CVE-2026-45659 | Tenable® https://t.co/SRRYYVs3Jv

    @endi24

    19 Jul 2026

    2542 Impressions

    5 Retweets

    23 Likes

    18 Bookmarks

    0 Replies

    0 Quotes

  15. 【緊急】CVE-2026-56164 MicrosoftのSharePoint Serverに深刻な脆弱性|即時対応が必要 https://t.co/yfmppfD9WK #IT #Security #cybersecurity

    @Teeeda_worker

    19 Jul 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🚨 CISA KEV Deadlines This Week 📅 Jul 17: SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) + Code Injection (CVE-2026-15410) | Microsoft SharePoint Missing Auth (CVE-2026-56164, CVSS 9.8) 📅 Jul 18: Oracle E-Business Suite Improper Privilege Management (CVE-2026-46817,

    @techepages

    18 Jul 2026

    76 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/denoKmLMkf https://t.co/lvM94DeVpG

    @EAlexStark

    17 Jul 2026

    69 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. July 2026 Patch Tuesday drops 622 CVEs with three zero-days: SharePoint (CVE-2026-56164) and AD FS (CVE-2026-56155) are actively exploited and CISA KEV-listed. #DFIR_Radar https://t.co/pLY8VaBF7d

    @DFIR_Radar

    17 Jul 2026

    189 Impressions

    1 Retweet

    3 Likes

    1 Bookmark

    2 Replies

    0 Quotes

  19. Microsoft Patch Tuesday: Rekord-breaking 622 CVEs. Zwei Zero-Days (CVE-2026-56155, CVE-2026-56164) werden aktiv ausgenutzt. Sofort patchen! #PatchTuesday #CyberSecurity https://t.co/dKB08AxiKK

    @wall_your_x

    17 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/Qr0dCd19Nh https://t.co/wD4LUwwYHc

    @dansantanna

    17 Jul 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. MS Patch Tuesday (Jul 14/15) addressed active zero-days: CVE-2026-56164 (SharePoint) & CVE-2026-56155 (ADFS) enable privilege escalation. SonicWall SMA1000 zero-days also exploited. Data integrity/privacy at risk. #Cybersecurity #InfoSec #Vulnerabilities

    @YourAnon_irc

    17 Jul 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. Four on-premises SharePoint Server CVEs are actively exploited: CVE-2026-32201 (CVSS 6.5), CVE-2026-45659 (CVSS 8.8), CVE-2026-56164 (CVSS 9.8), and CVE-2026-58644 (CVSS 9.8). #DFIR_Radar https://t.co/ln2QdK28Q8

    @DFIR_Radar

    17 Jul 2026

    190 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    2 Replies

    0 Quotes

  23. 🛡️ Microsoft's July Patch Tuesday: 622 CVEs, the largest on record. Two under active attack — CVE-2026-56164 (SharePoint) and CVE-2026-56155 (AD FS). What's exploitable and what to patch first: https://t.co/YdTCg7eWT0

    @colibrisec

    16 Jul 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Exploitation Warnings for SharePoint Server Demand Immediate Action https://t.co/uVEGqZq5Sn #CVE2026 #SharePoint #CyberSecurity

    @cyber_newsroom

    16 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. 🚨 Microsoft July 2026 Patch Tuesday: 622 flaws fixed. 2 zero-days exploited. 🔴 CVE-2026-56164 — SharePoint 🔴 CVE-2026-56155 — AD FS Patch exploited identity and collaboration systems first. Don’t rely on CVSS alone. https://t.co/dGByZy5j04 #CyberSecurity #PatchTues

    @vulert_official

    16 Jul 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. Microsoft ships its biggest Patch Tuesday ever with 2 zero-days already exploited: AD FS (CVE-2026-56155) + SharePoint (CVE-2026-56164). Plus a 4th BitLocker bypass in 5 weeks (CVE-2026-50661). Patch now.  https://t.co/qs2aI4iwIR https://t.co/opbzEJk06M #CyberSecurity http

    @DIESEC_GmbH

    16 Jul 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. 🔎 V rámci červencového Patch Tuesday bylo opraveno rekordních 622 zranitelností. Dvě zero day chyby umožňující zvýšení oprávnění již byly aktivně zneužívány: ⚠️ CVE-2026-56164 v on-premises SharePoint Serveru ⚠️ CVE-2026-56155 v ADFS Třetí zero

    @sec4good

    16 Jul 2026

    60 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  28. Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164) https://t.co/dF0u4oO0St https://t.co/2Nnvf2s9pc

    @ggrubamn

    15 Jul 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. Microsoft just shipped 622 CVE patches — biggest release in company history — and 2 are already exploited. If you're on Windows and haven't updated this week, your machine is a soft target for CVE-2026-56164 (SharePoint) + CVE-2026-56155 (AD FS). Update tonight.

    @FaultSignal_

    15 Jul 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. CVE-2026-58644: SharePoint Server deserialization RCE (CVSS 9.8). Unauthenticated, network-exploitable. Sibling CVE demoed at Pwn2Own Berlin. Same July 14 patches as KEV-listed CVE-2026-56164. Investigation workflow → https://t.co/XV8bU4m3Ph

    @hellorecon

    15 Jul 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164) https://t.co/RIwE8jAnDX https://t.co/72juYIrOoL

    @secured_cyber

    15 Jul 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. These security flaws (tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) affect all supported self-hosted SharePoint Server versions. https://t.co/q9ukzEgfYf

    @jbhall56

    15 Jul 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. Running SharePoint? There are at least 4 vulns you want to pay attention to: CVE-2026-55040, CVE-2026-52522, CVE-2026-58644, CVE-2026-56164 unauthenticated RCE, exploits available etc. https://t.co/9moTd0gNju

    @theluemmel

    15 Jul 2026

    2063 Impressions

    2 Retweets

    16 Likes

    8 Bookmarks

    2 Replies

    0 Quotes

  34. 🚨 CISA deadline alert: 3 actively exploited flaws must be patched by July 17 🔹 CVE-2026-15409: SonicWall SMA1000 SSRF — unauthenticated remote exploitation 🔹 CVE-2026-15410: SonicWall SMA1000 code injection enables admin OS commands 🔹 CVE-2026-56164: SharePoint mis

    @techepages

    15 Jul 2026

    70 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  35. Microsoft patches 3 zero-days in July 2026 Patch Tuesday — 2 already under attack 🚨 🔹 CVE-2026-56155: AD FS flaw grants admin privileges, exploited in the wild 🔹 CVE-2026-56164: SharePoint bug lets remote attackers elevate privileges 🔹 CVE-2026-50661: BitLocker byp

    @techepages

    15 Jul 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. 🔒 #CyberSecurity CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: SharePoint Server Active Exploi… "On July 14, 2026, CISA issued an urgent alert regarding active exploitation of…" 🔗 https://t.co/A0C48eSEX9 #CyberSecurity #ThreatIntel #managedsoc #mdr #securitymonito

    @SecurityAr58409

    15 Jul 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. 🔒 #CyberSecurity CVE-2026-56164: Microsoft SharePoint Server Exploitation — Detection and Remedi… "On July 14, 2026, CISA added CVE-2026-56164, affecting Microsoft SharePoint Server,…" 🔗 https://t.co/C2fuYYWcEe #CyberSecurity #ThreatIntel #cve202656164 #critical #

    @SecurityAr58409

    15 Jul 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. CISA warns SharePoint vulnerabilities CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 are exploited in the wild. Patch and harden servers now. #CISA #SharePoint #Microsoft #CVE #CyberSecurity https://t.co/SN49kOAPnL

    @Daily_CyberSec

    15 Jul 2026

    375 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  39. 【脆弱性の嵐】マイクロソフトさん、月例更新で史上最多となる622件の脆弱性を修正。ゼロデイはADFSのCVE-2026-56155とSharePointのCVE-2026-56164の2件。他外部指摘は物理でのBitLocker回避CVE-2026-50661。 https://t.co/zJK92NBTQE

    @__kokumoto

    14 Jul 2026

    1910 Impressions

    4 Retweets

    15 Likes

    3 Bookmarks

    1 Reply

    1 Quote

  40. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。月次更新関連。SonicWall SMA1000のCVE-2026-15409とCVE-2026-15410、ADFSのCVE-2026-56155、SharePointのCVE-2026-56164。

    @__kokumoto

    14 Jul 2026

    2150 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    1 Reply

    1 Quote

  41. Microsoft's July 2026 Patch Tuesday fixes 570 flaws. Zero-days CVE-2026-56155 and CVE-2026-56164 are exploited in the wild. Patch now. #PatchTuesday #Microsoft #ZeroDay #CVE #CyberSecurity https://t.co/cdi7Tiqj27

    @Daily_CyberSec

    14 Jul 2026

    339 Impressions

    3 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  42. 🚨 Microsoft Patch Tuesday (July 2026): Microsoft has patched ~570 vulnerabilities, including critical RCE flaws and three publicly disclosed issues: CVE-2026-56164, CVE-2026-56155, and CVE-2026-50661. #CyberSecurity #Microsoft #PatchTuesday #CVE #ThreatWire

    @ThreatWire_

    14 Jul 2026

    75 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  43. Microsoft’s July 2026 Patch Tuesday delivers fixes for approximately 570 vulnerabilities across its product ecosystem, following June’s record-breaking release of 206 flaws that also included three publicly disclosed zero-days. 📌 CVE-2026-56164 📌 CVE-2026-56155 📌 ht

    @The_Cyber_News

    14 Jul 2026

    7760 Impressions

    33 Retweets

    130 Likes

    27 Bookmarks

    5 Replies

    0 Quotes