SharePoint Server unauthenticated privilege escalation flaw actively exploited (CVE-2026-56164)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-56164 is an actively exploited SharePoint Server vulnerability that lets an unauthenticated attacker escalate privileges over the network. The flaw puts on-premises SharePoint Server deployments at immediate risk, especially where the service is exposed to remote access. Microsoft has already identified it as a fix-first issue for July 2026.
Cases
Related Happenings
SharePoint exploitation wave
Exploitation Wave
H score42
First: 22.07.2026 14:29
Last: 22.07.2026 14:29
Sources 1
About this happening:
In-the-wild exploitation of SharePoint flaws has expanded to a fourth case in the past month, increasing the risk to exposed SharePoint instances.
SharePoint exploitation wave
Exploitation WaveAbout this happening: In-the-wild exploitation of SharePoint flaws has expanded to a fourth case in the past month, increasing the risk to exposed SharePoint instances.
CISA Microsoft SharePoint hardening guidance for exploited zero-days
Advisory/Mitigation
H score56
First: 15.07.2026 17:07
Last: 15.07.2026 17:07
Sources 1
How related:
The US Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday urged immediate hardening of Microsoft SharePoint servers in light of recently disclosed zero-day vulnerabilities.
About this happening:
CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...
CISA Microsoft SharePoint hardening guidance for exploited zero-days
Advisory/MitigationHow related: The US Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday urged immediate hardening of Microsoft SharePoint servers in light of recently disclosed zero-day vulnerabilities.
About this happening: CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...
Microsoft SharePoint Server actively exploited multi-CVE wave
Exploitation Wave
H score79
First: 15.07.2026 12:44
Last: 15.07.2026 12:44
Sources 1
How related:
“These vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution (RCE) and post-exploitation activities, such as stealing Internet Information Services (IIS) machine keys and performing deserialization techniques, to gain persistence and deploy malware,” CISA warns.
About this happening:
SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...
Microsoft SharePoint Server actively exploited multi-CVE wave
Exploitation WaveHow related: “These vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution (RCE) and post-exploitation activities, such as stealing Internet Information Services (IIS) machine keys and performing deserialization techniques, to gain persistence and deploy malware,” CISA warns.
About this happening: SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...
CISA BOD 26-04 SharePoint remediation deadline
Public Sector Action
H score77
First: 15.07.2026 12:44
Last: 15.07.2026 12:44
Sources 1
How related:
On Tuesday, CISA added the CVE to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days, in line with BOD 26-04 recommendations.
About this happening:
CISA gave federal agencies until July 17 to secure or discontinue SharePoint servers affected by CVE-2026-56164, turning the remediation deadline into a mandatory...
CISA BOD 26-04 SharePoint remediation deadline
Public Sector ActionHow related: On Tuesday, CISA added the CVE to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days, in line with BOD 26-04 recommendations.
About this happening: CISA gave federal agencies until July 17 to secure or discontinue SharePoint servers affected by CVE-2026-56164, turning the remediation deadline into a mandatory...
Microsoft Copilot remote code execution flaw (CVE-2026-48561)
Vulnerability
H score33
First: 14.07.2026 22:22
Last: 14.07.2026 22:22
Sources 1
About this happening:
A CVE-2026-48561 remote code execution flaw in Microsoft Copilot can let an unauthorized attacker execute code over the network, creating remote takeover risk for affected...
Microsoft Copilot remote code execution flaw (CVE-2026-48561)
VulnerabilityAbout this happening: A CVE-2026-48561 remote code execution flaw in Microsoft Copilot can let an unauthorized attacker execute code over the network, creating remote takeover risk for affected...
Timeline
-
15.07.2026 12:20 4 articles · 13d ago
Microsoft patches exploited SharePoint Server zero-day CVE-2026-56164
Mitigation Patch UpdateMicrosoft’s July 14 Patch Tuesday included CVE-2026-56164, an elevation-of-privilege flaw in Microsoft SharePoint Server that required no existing privileges and was described as low complexity. The zero-day was one of two vulnerabilities in the release that had been exploited in the wild, and Microsoft issued updates for affected systems.
Show sources
- Microsoft Patches 570 CVEs in Record Patch Tuesday — www.infosecurity-magazine.com — 15.07.2026 12:20
- Microsoft Patches 570 CVEs in Record Patch Tuesday — www.infosecurity-magazine.com — 15.07.2026 12:20
- CISA warns admins to patch actively exploited SharePoint flaws — www.bleepingcomputer.com — 15.07.2026 12:44
- CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities — www.securityweek.com — 15.07.2026 17:07
-
14.07.2026 23:25 2 articles · 13d ago
CVE-2026-56164 is exploited in on-premises SharePoint Server attacks
Exploitation ObservedMicrosoft says CVE-2026-56164 in on-premises SharePoint Server is being exploited in attacks, letting an unauthenticated attacker escalate privileges over the network; Microsoft credits Mandiant incident responders and Google's FLARE team for the discovery.
Show sources
- Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack — thehackernews.com — 14.07.2026 23:25
- Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack — thehackernews.com — 14.07.2026 23:25
-
14.07.2026 23:25 1 articles · 13d ago
Microsoft ships the SharePoint Server fix for CVE-2026-56164
Mitigation Patch UpdateMicrosoft's July Patch Tuesday ships the fix for CVE-2026-56164 in on-premises SharePoint Server, and the advisory says enabling AMSI in Full Mode on the server can blunt the attack path if immediate patching is not possible.
Show sources
- Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack — thehackernews.com — 14.07.2026 23:25