cbcvebase.
CVE-2026-56164
published 2026-07-14

CVE-2026-56164: Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

PriorityP197critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-07-17
Exploited in the wild
EPSS
18.39%
96.9th percentile
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

Affected

6 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_sharepoint_enterprise_server_2016>= 16.0.0 < 16.0.5561.100116.0.5561.1001
microsoftmicrosoft_sharepoint_server_2019>= 16.0.0 < 16.0.10417.2017516.0.10417.20175
microsoftmicrosoft_sharepoint_server_subscription_edition>= 16.0.0 < 16.0.19725.2043416.0.19725.20434
microsoftsharepoint_server< 16.0.19725.2043416.0.19725.20434
microsoftsharepoint_server
microsoftsharepoint_server

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2026-56164 is actively exploited in the wild; detect unauthenticated network requests reaching SharePoint Server endpoints that should require authentication — specifically requests that succeed without valid credentials and result in privilege escalation.
  • Alert on deserialization activity originating from SharePoint worker processes following unauthenticated requests — a post-exploitation technique observed in active exploitation of CVE-2026-56164.
  • CVE-2026-56164 requires no prior authentication or user interaction; block or closely monitor all external/unauthenticated network access to on-premises SharePoint Server administrative and privileged function endpoints.
  • ·CVE-2026-56164 affects all supported on-premises SharePoint Server versions only (Subscription Edition, 2019, and 2016); scope detection and patching efforts accordingly.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.