Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Advisory/Mitigation Exploitation Wave Public Sector Action Security Patch Release

Active SharePoint exploitation around CVE-2026-56164 drives patching and federal response

Updated 17.07.2026 09:42
Case score 86
Members 5 First seen 14.07.2026 23:25 Latest activity 17.07.2026 09:42

Overview

**Microsoft SharePoint Server** exploitation around **CVE-2026-56164** remains an urgent risk for on-premises deployments, with separate reporting also tracking attacks involving **CVE-2026-32201** and **CVE-2026-45659** on internet-exposed systems. Reported post-compromise activity includes **IIS machine key** theft, persistence, and malware deployment, raising concern that patching alone may not fully remove attacker access from already-hit servers. Microsoft shipped SharePoint fixes in its July updates, while CISA urged immediate hardening and gave U.S. federal agencies until **July 17** to secure or discontinue affected systems.
Latest development Open development history 3 earlier developments Microsoft patches exploited SharePoint Server zero-day CVE-2026-56164 Microsoft’s July 14 Patch Tuesday included CVE-2026-56164, an elevation-of-privilege flaw in Microsoft SharePoint Server that required no existing privileges and was described as low complexity. The zero-day was one of two vulnerabilities in the release that had been exploited in the wild, and Microsoft issued updates for affected systems.
  1. Earlier development

    SharePoint Server and AD FS flaws expose privilege escalation paths

    CVE-2026-56164 in on-premises SharePoint Server allows an unauthenticated attacker to escalate privileges over the network, while CVE-2026-56155 in Active Directory Federation Services allows an already-authenticated attacker to elevate privileges locally through weak access controls. Microsoft credits Mandiant incident responders, Google's FLARE team, and Microsoft's DART incident-response unit with the discoveries, pointing to active attack investigation around both flaws.

  2. Earlier development

    Microsoft removes the Kerberos RC4 rollback switch

    Microsoft's July rollout removes the RC4DefaultDisablementPhase rollback switch, so RC4 works only for accounts explicitly configured to allow it. Administrators are told to audit RC4 usage, rotate passwords on flagged service accounts to generate AES keys, and patch before legacy services or clients lose authentication.

  3. Earlier development

    CVE-2026-56164 is exploited in on-premises SharePoint Server attacks

    Microsoft says CVE-2026-56164 in on-premises SharePoint Server is being exploited in attacks, letting an unauthenticated attacker escalate privileges over the network; Microsoft credits Mandiant incident responders and Google's FLARE team for the discovery.

Signals

Impact signals
Exploitation
Affected impact
CVEs/products
Geographic context
Remediation
Status
Threat context

Tooling context

4 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Vulnerability SharePoint Server unauthenticated privilege escalation flaw actively exploited (CVE-2026-56164)
Updated 14.07.2026 23:25 Lead Contribution 82
Exploitation Active Exploitation Data Type Passwords CVSS 9.9 Critical Patch Patch Available

**CVE-2026-56164** is an **actively exploited** **SharePoint Server** vulnerability that lets an unauthenticated attacker **escalate privileges over the network**. The flaw puts **on-premises SharePoint Server** deployments at immediate risk, especially where the service is exposed to remote access. Microsoft has already identified it as a fix-first issue for July 2026.

Exploitation Wave Microsoft SharePoint Server actively exploited multi-CVE wave
Updated 15.07.2026 12:44 Scoring Support Contribution 4
Exploitation Active Exploitation CVSS 9.8 Critical Patch Patch Available

**SharePoint Server** exploitation wave remains active across **internet-exposed on-premises instances**, with **CVE-2026-32201**, **CVE-2026-45659**, and **CVE-2026-56164** used to bypass authentication, reach **remote code execution**, and enable **IIS machine key theft**, persistence, and malware deployment. **CISA** added the exploited CVEs to the **Known Exploited Vulnerabilities Catalog** and urged operators to apply **Microsoft's latest patches**, verify installation, enable **AMSI** and **Microsoft Defender Antivirus** detections, reduce direct internet exposure, block **SharePoint Central Administration**, and use a **Layer 7 reverse proxy** where needed.

Public Sector Action CISA BOD 26-04 SharePoint remediation deadline
Updated 15.07.2026 12:44 Context
Policy Stage Enforced Patch Patch Available

**CISA** gave federal agencies until **July 17** to secure or discontinue **SharePoint servers** affected by **CVE-2026-56164**, turning the remediation deadline into a mandatory federal action for exposed systems. The agency had already added **CVE-2026-32201**, **CVE-2026-45659**, and **CVE-2026-56164** to the **Known Exploited Vulnerabilities Catalog** on **April 14**, **July 1**, and **July 14**. Agencies that cannot apply mitigations must **discontinue** the affected servers under **BOD 26-04**.

Advisory/Mitigation CISA Microsoft SharePoint hardening guidance for exploited zero-days
Updated 15.07.2026 17:07 Context
Exploitation Active Exploitation CVSS 9.8 Critical Urgency Immediate Patch Patch Available

CISA’s **Microsoft SharePoint servers** hardening guidance responds to newly disclosed **zero-day vulnerabilities** that can be exploited remotely, creating immediate risk for supported on-premises deployments. **CVE-2026-56164** was added to the **KEV catalog**, and federal agencies must patch it within **three days** under **BOD 26-04**. Microsoft’s **July 2026 Patch Tuesday** also resolved **CVE-2026-55040** and **CVE-2026-58644**, while CISA urged monitoring, intrusion hunting, and tighter exposure controls.

Security Patch Release Microsoft security patch release for CVE-2026-56164
Updated 14.07.2026 23:25 Context
Exploitation Active Exploitation CVSS 9.9 Critical Urgency Immediate Patch Patch Available

Microsoft released a **record 622-CVE Patch Tuesday** that includes **two exploited flaws** in **SharePoint Server** and **Active Directory Federation Services**, raising urgency for identity and collaboration systems. The top-priority fixes are **CVE-2026-56164** and **CVE-2026-56155**, both elevation-of-privilege bugs already being used in attacks. Microsoft also bundled additional updates across **Windows**, **Office**, **Edge**, **Azure**, **Defender**, and developer tools. The release matters because defenders must triage a much larger-than-usual update set while attackers can immediately focus on the flaws already in use.