CVE-2026-56164
published 2026-07-14CVE-2026-56164: Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
PriorityP197critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-07-17
Exploited in the wild
EPSS
18.39%
96.9th percentile
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < 16.0.5561.1001 | 16.0.5561.1001 |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < 16.0.10417.20175 | 16.0.10417.20175 |
| microsoft | microsoft_sharepoint_server_subscription_edition | >= 16.0.0 < 16.0.19725.20434 | 16.0.19725.20434 |
| microsoft | sharepoint_server | < 16.0.19725.20434 | 16.0.19725.20434 |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2026-56164 is actively exploited in the wild; detect unauthenticated network requests reaching SharePoint Server endpoints that should require authentication — specifically requests that succeed without valid credentials and result in privilege escalation. ↗
- →Alert on deserialization activity originating from SharePoint worker processes following unauthenticated requests — a post-exploitation technique observed in active exploitation of CVE-2026-56164. ↗
- →CVE-2026-56164 requires no prior authentication or user interaction; block or closely monitor all external/unauthenticated network access to on-premises SharePoint Server administrative and privileged function endpoints. ↗
- ·CVE-2026-56164 affects all supported on-premises SharePoint Server versions only (Subscription Edition, 2019, and 2016); scope detection and patching efforts accordingly. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
ghsa_unreviewed·2026-07-14
CVE-2026-56164 [MEDIUM] CWE-306 Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
VulDB
Microsoft SharePoint Server Critical Function missing authentication
vuldb·2026-07-14·CVSS 9.8
CVE-2026-56164 [CRITICAL] Microsoft SharePoint Server Critical Function missing authentication
A vulnerability, which was classified as very critical, has been found in Microsoft SharePoint Server. This vulnerability affects unknown code of the component Critical Function. The manipulation leads to missing authentication.
This vulnerability is documented as CVE-2026-56164. The attack can be initiated remotely. Additionally, an exploit exists.
VulnCheck
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
vulncheck·2026·CVSS 9.8
CVE-2026-56164 [CRITICAL] CWE-306 Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
Affected: Microsoft SharePoint
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Exploi
CISA
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
cisa·2026-07-14·CVSS 9.8
CVE-2026-56164 [CRITICAL] CWE-306 Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
Vulnerability: Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
Affected: Microsoft SharePoint Server
Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patchin
No detection rules found.
No public exploits indexed.
Tenable
Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness
blogs_tenable·2026-07-21
CVE-2026-63030 Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness
## Your AI agent’s config is now the payload: How attackers are targeting the developer agent harness
Attackers have shifted from hiding from AI tools to running inside them. By poisoning the config files that govern AI coding assistants, a new worm class achieves silent persistence, evades AI-based scanners, and spreads across an organization's repositories through developers' own tools.
## Key takeaways
AI coding assistant configuration files, such as settings.json hooks, .cursorrules Cursor MDC rules, and similar harness files, are now explicit targets in supply-chain attacks, not collateral damage.
These files simultaneously sit at the intersection of three trust relationships: The developer trusts them as config, the integrated development environment (IDE) executes them automatic
Hackernews
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
blogs_hackernews·2026-07-21·CVSS 9.8
CVE-2026-50522 [CRITICAL] Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr .
The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network. Microsoft credited DEVCORE researcher "splitline" with discovering and reporting the flaw.
"In a network-based attack, an attacker authenticated as at least a Site Owner, could w
Tenable
Oracle July 2026 Critical Patch Update Addresses 1235 CVEs
blogs_tenable·2026-07-21
CVE-2026-63030 Oracle July 2026 Critical Patch Update Addresses 1235 CVEs
## Oracle July 2026 Critical Patch Update Addresses 1235 CVEs
Oracle addresses 1235 CVEs in its third quarterly update of 2026 with 1449 patches, including 261 critical updates.
## Key Takeaways
The third Critical Patch Update (CPU) for 2026 contains fixes for 1235 unique CVEs in 1449 security updates, the largest CPU release.
261 issues (18% of all patches) were assigned a critical severity rating
Oracle E-Business Suite received the highest number of patches at 410, accounting for 28.3% of all patches
## Background
On July 21, Oracle released its Critical Patch Update (CPU) for July 2026 , the third quarterly update of the year. This CPU contains fixes for 1235 unique CVEs in 1449 security updates across 32 Oracle product families. Out of the 1449 security updates published this q
Checkpoint
20th July – Threat Intelligence Report
blogs_checkpoint·2026-07-20
CVE-2026-56164 20th July – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 20th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, employee details, and other sensitive information submitted while requesting technical assistance.
Jscrambler,
Tenable
wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
blogs_tenable·2026-07-20·CVSS 5.9
CVE-2026-63030 [MEDIUM] wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
## wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public proof-of-concept exploits are circulating.
## Key takeaways:
Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve pre-authentication remote code execution against WordPress 6.9.x and 7.0.x installations.
Multiple security firms have confirmed in-the-wild exploitation, with public proof-of-concept exploits appearing w
Hackernews
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
blogs_hackernews·2026-07-20·CVSS 5.9
CVE-2026-63030 [MEDIUM] ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.
The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch.
Here is the full recap of what broke, what was exploited, and what needs attention now.
## ⚡ Threat of the Week
New wp2shell WordPress Core Flaw Lets Unauthe
Hackernews
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
blogs_hackernews·2026-07-17·CVSS 6.5
CVE-2026-58644 [MEDIUM] CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities ( KEV ) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026.
The vulnerability in question is CVE-2026-58644 (CVSS score: 9.8), a critical deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute arbitrary code.
"In a network-based attack, an attacker authenticated as at least a Sit
Tenable
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
blogs_tenable·2026-07-16·CVSS 6.5
CVE-2026-32201 [MEDIUM] CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
## CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments.
## Key Takeaways
CISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware for persistence.
Two additional SharePoint Server vulnerabilities disclosed on July 14, 2026, CVE-2026-55040 and CVE-2026-58644, were not yet
Tenable
The best defenders build AI agents together: Join Tenable for Swarm at Black Hat ’26
blogs_tenable·2026-07-16
CVE-2026-32201 The best defenders build AI agents together: Join Tenable for Swarm at Black Hat ’26
## The best defenders build AI agents together: Join Tenable for Swarm at Black Hat ’26
Agentic AI use is exploding, yet most security teams are building agents in isolation. Tenable is hosting Swarm, a build event at Black Hat 2026, for security practitioners to create and collaborate on agentic, open-source tooling to drive collective defense and stop adversaries together.
## Key takeaways
According to Gartner®, by 2028, an average global Fortune 500 enterprise will have more than 150,000 AI agents in use, up from less than 15 in 2025, generating significant agent sprawl, IT complexity, and management challenges. 1
Security practitioners are building their own agentic, open-source tooling to cut out hours of manual phishing email triage, accelerate threat hunts, and uplevel junior ta
Hackernews
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
blogs_hackernews·2026-07-15
CVE-2026-56164 Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse ) has released a new proof-of-concept (PoC) exploit called LegacyHive.
It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. The Windows User Profile Service, also referred to as ProfSvc, is a core system component that manages user accounts and environments.
"The PoC requires another standard user credential and a third username (which can be an administrator account)," Chaotic Eclipse said . "If the PoC is successful, it will e
Hackernews
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
blogs_hackernews·2026-07-15·CVSS 7.8
CVE-2026-56164 [HIGH] Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft's own CVEs by its Security Update Guide count, more than triple June's previous high of around 200 .
Those two live bugs are the ones to grab first. Microsoft credits incident responders for both. Both are elevation-of-privilege flaws in identity and collaboration infrastructure: CVE-2026-56164 in on-premises SharePoint Server and CVE-2026-56155 in Active Directory Federation Serv
Rapid7
Patch Tuesday - July 2026
blogs_rapid7·2026-07-14·CVSS 9.6
CVE-2026-58617 [CRITICAL] Patch Tuesday - July 2026
Microsoft is publishing 622 vulnerabilities on July 2026 Patch Tuesday , including a record-breaking 416 Windows vulnerabilities. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today, both of which are listed on CISA KEV, as well as public disclosure for one other. As usual, browser vulns are not included in the Patch Tuesday count above. Rapid7 noted last month that Microsoft no longer enumerates Chromium CVEs in the Security Update Guide. However, Microsoft has now taken the pursuit of minimalism much further, since today’s Security Update Guide no longer lists out even Microsoft vulnerabilities! Instead, we now receive a summary table of vulnerability counts by product family, as well as a new slimline “Notable CVEs” section. All of this only ser
Talos
Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
blogs_talos·2026-07-14·CVSS 8.8
CVE-2026-56155 [HIGH] Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical".
Microsoft notes that two of the vulnerabilities disclosed this month have been exploited in the wild.
CVE-2026-56155 is an important-severity elevation of privilege vulnerability in Active Directory Federation Services (AD FS) caused by insufficient granularity of access control. An authorized attacker could use it to elevate privileges locally.
CVE-2026-56164 is a moderate-severity vulnerability in Microsoft SharePoint Server caused by missing authentication for a critical function. An unauthorized attacker could exploit i
Sans Isc
Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)
blogs_sans_isc·2026-07-14·CVSS 6.1
CVE-2026-56155 [MEDIUM] Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th)
Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here
Published: 2026-07-14. Last Updated: 2026-07-14 19:14:58 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
This patch Tuesday includes a staggering 622 vulnerabilities, not including another 427 vulnerabilities in Chromium, affecting Microsoft's Edge browser. 62 of the vulnerabilities are rated critical. One was disclosed before today, and two have already been exploited.
Given the large number of vulnerabilities, it is difficult to point out "noteworthy" issues.
Already exploited vulnerabilities:
CVE-2026-56155 : Active Directory Federation Services Elevation of Privilege Vulnerability. This is an important (not critical) vulnerablity.
CVE-2026-56164: Microsoft SharePoint Server Elevation of Privilege Vulnerability. Micr
Krebs
Microsoft Patches a Record 570 Security Flaws
blogs_krebs·2026-07-14·CVSS 9.6
CVE-2026-56155 [CRITICAL] Microsoft Patches a Record 570 Security Flaws
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.
Nearly 60 of the bugs quashed in July’s Patch Tuesday earned a “critical” severity rating, meaning miscreants or malware could use them to seize remote control over a Windows device with little or no help from the user. Microsoft also addressed three zero-day flaws, including two that are already being exploited in the wild.
Two of the zero-day weaknesses allow an attacker to elevate their user rights on a Windows syste
Qualys
Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review
blogs_qualys·2026-07-14
CVE-2026-50661 Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review
## Table of Contents
Microsoft Patch Tuesday forJuly2026
Adobe Patch for July 2026
Zero-day Vulnerabilities Patched inJulyPatch Tuesday Edition
Critical Severity Vulnerabilities Patched inJulyPatch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Qualys Monthly Webinar Series
Microsoft’s July 2026 Patch Tuesday delivers security updates for a broad range of products and services, including several vulnerabilities that pose significant risks to enterprise environments. As attackers continue to target unpatched systems, the timely deployment of these updates remains one of the most effective defenses against exploitation. This blog provides an overview of the month’s key security fixes, highlights the most critical vulnerabilities, and offers guidanc
Tenable
Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)
blogs_tenable·2026-07-14·CVSS 7.8
CVE-2026-56155 [HIGH] Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)
## Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)
56 Critical
510 Important
3 Moderate
0 Low
Microsoft addresses 569 CVEs in the largest Patch Tuesday release yet. This month’s release includes three zero-days, two of which were exploited in the wild.
Microsoft patched 569 CVEs in its July 2026 Patch Tuesday release, with 56 rated critical, 510 rated as important, and 3 rated as moderate. This marks the largest Patch Tuesday release ever, crushing the previous record of 198 CVEs in June . Last week, Microsoft announced that its multi-model agentic scanning harness (MDASH) is being used to identify vulnerabilities faster and noted that “customers will see a higher volume of security updates included in each security release.”
This month’s upda
Crowdstrike
July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days
blogs_crowdstrike
CVE-2026-56155 July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days
AIDR: How CrowdStrike Is Defining the Next Era of Cybersecurity Jul 15, 2026
July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days Jul 14, 2026
Why AI Governance Without Guardrails Is Theater Jul 09, 2026
Falcon Secure Access Sets the Standard for Zero Trust Browser Security Jul 08, 2026
AIDR: How CrowdStrike Is Defining the Next Era of Cybersecurity Jul 15, 2026
July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days Jul 14, 2026
Why AI Governance Without Guardrails Is Theater Jul 09, 2026
Falcon Secure Access Sets the Standard for Zero Trust Browser Security Jul 08, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&
2026-07-14
Published
2026-07-14
Added to CISA KEV
Exploited in the wild