Find notable cyber news and cases, enriched with sources, timelines, and signals.

SharePoint Server unauthenticated privilege escalation flaw actively exploited (CVE-2026-56164)

Vulnerability
First reported
Last updated
Happening score
H score 82
4 unique sources, 4 articles

Summary

Hide ▲

CVE-2026-56164 is an actively exploited SharePoint Server vulnerability that lets an unauthenticated attacker escalate privileges over the network. The flaw puts on-premises SharePoint Server deployments at immediate risk, especially where the service is exposed to remote access. Microsoft has already identified it as a fix-first issue for July 2026.

Cases

Related Happenings

SharePoint exploitation wave

Exploitation Wave
H score42 First: 22.07.2026 14:29 Last: 22.07.2026 14:29 Sources 1

About this happening: In-the-wild exploitation of SharePoint flaws has expanded to a fourth case in the past month, increasing the risk to exposed SharePoint instances.

CISA Microsoft SharePoint hardening guidance for exploited zero-days

Advisory/Mitigation
H score56 First: 15.07.2026 17:07 Last: 15.07.2026 17:07 Sources 1

How related: The US Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday urged immediate hardening of Microsoft SharePoint servers in light of recently disclosed zero-day vulnerabilities.

About this happening: CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...

Microsoft SharePoint Server actively exploited multi-CVE wave

Exploitation Wave
H score79 First: 15.07.2026 12:44 Last: 15.07.2026 12:44 Sources 1

How related: “These vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution (RCE) and post-exploitation activities, such as stealing Internet Information Services (IIS) machine keys and performing deserialization techniques, to gain persistence and deploy malware,” CISA warns.

About this happening: SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...

CISA BOD 26-04 SharePoint remediation deadline

Public Sector Action
H score77 First: 15.07.2026 12:44 Last: 15.07.2026 12:44 Sources 1

How related: On Tuesday, CISA added the CVE to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days, in line with BOD 26-04 recommendations.

About this happening: CISA gave federal agencies until July 17 to secure or discontinue SharePoint servers affected by CVE-2026-56164, turning the remediation deadline into a mandatory...

Microsoft Copilot remote code execution flaw (CVE-2026-48561)

Vulnerability
H score33 First: 14.07.2026 22:22 Last: 14.07.2026 22:22 Sources 1

About this happening: A CVE-2026-48561 remote code execution flaw in Microsoft Copilot can let an unauthorized attacker execute code over the network, creating remote takeover risk for affected...

Timeline

  1. 15.07.2026 12:20 4 articles · 13d ago

    Microsoft patches exploited SharePoint Server zero-day CVE-2026-56164

    Mitigation Patch Update

    Microsoft’s July 14 Patch Tuesday included CVE-2026-56164, an elevation-of-privilege flaw in Microsoft SharePoint Server that required no existing privileges and was described as low complexity. The zero-day was one of two vulnerabilities in the release that had been exploited in the wild, and Microsoft issued updates for affected systems.

    Show sources
  2. 14.07.2026 23:25 2 articles · 13d ago

    CVE-2026-56164 is exploited in on-premises SharePoint Server attacks

    Exploitation Observed

    Microsoft says CVE-2026-56164 in on-premises SharePoint Server is being exploited in attacks, letting an unauthenticated attacker escalate privileges over the network; Microsoft credits Mandiant incident responders and Google's FLARE team for the discovery.

    Show sources
  3. 14.07.2026 23:25 1 articles · 13d ago

    Microsoft ships the SharePoint Server fix for CVE-2026-56164

    Mitigation Patch Update

    Microsoft's July Patch Tuesday ships the fix for CVE-2026-56164 in on-premises SharePoint Server, and the advisory says enabling AMSI in Full Mode on the server can blunt the attack path if immediate patching is not possible.

    Show sources