Active SharePoint exploitation around CVE-2026-56164 drives patching and federal response
Case score 86
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 86
- Main story score
- 82
- Related evidence lift
- +4 / 20
- Contributing updates
- 1
- Context updates
- 3
- Vulnerability Primary anchor for active exploitation of CVE-2026-56164 in on-premises SharePoint Server. main
- Public Sector Action Adds the July 17 federal deadline and discontinuation requirement for affected SharePoint servers. context
- Exploitation Wave Adds the broader exploited SharePoint flaw set and reported post-compromise behavior on internet-exposed servers. contributes
- Security Patch Release Provides SharePoint patch availability for CVE-2026-56164 and related July update context. context
Overview
Latest development Open development history Microsoft patches exploited SharePoint Server zero-day CVE-2026-56164 Microsoft’s July 14 Patch Tuesday included CVE-2026-56164, an elevation-of-privilege flaw in Microsoft SharePoint Server that required no existing privileges and was described as low complexity. The zero-day was one of two vulnerabilities in the release that had been exploited in the wild, and Microsoft issued updates for affected systems.
-
SharePoint Server and AD FS flaws expose privilege escalation paths
CVE-2026-56164 in on-premises SharePoint Server allows an unauthenticated attacker to escalate privileges over the network, while CVE-2026-56155 in Active Directory Federation Services allows an already-authenticated attacker to elevate privileges locally through weak access controls. Microsoft credits Mandiant incident responders, Google's FLARE team, and Microsoft's DART incident-response unit with the discoveries, pointing to active attack investigation around both flaws.
-
Microsoft removes the Kerberos RC4 rollback switch
Microsoft's July rollout removes the RC4DefaultDisablementPhase rollback switch, so RC4 works only for accounts explicitly configured to allow it. Administrators are told to audit RC4 usage, rotate passwords on flagged service accounts to generate AES keys, and patch before legacy services or clients lose authentication.
-
CVE-2026-56164 is exploited in on-premises SharePoint Server attacks
Microsoft says CVE-2026-56164 in on-premises SharePoint Server is being exploited in attacks, letting an unauthenticated attacker escalate privileges over the network; Microsoft credits Mandiant incident responders and Google's FLARE team for the discovery.