Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-56164

Published 2026-07-14
Updated 2 months ago
Vendor/s
Microsoft
Product/s
SharePoint Server
Version/s
* > 16.0.19725.20434
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
5.3
/ 10
Medium
Severity Details
Base score
5.3 Medium
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Description

CVE-2026-56164 is a privilege escalation vulnerability in Microsoft SharePoint Server with active exploitation. Patch affected versions immediately.

CPE

Microsoft logo
Microsoft
Product Version Start Version End (excl.) Status
sharepoint_server * 16.0.19725.20434 vulnerable
sharepoint_server 2016 2016 vulnerable
sharepoint_server 2019 2019 vulnerable

Related weakness (CWE)

CWE-306

Remediation plan

1

Apply official patches

Download and install the security updates provided by Microsoft via the MSRC Update Guide for your specific version of SharePoint Server to address the missing authentication flaw.

2

Update affected systems

Ensure all SharePoint Server instances are updated beyond version 16.0.19725.20434. This includes applying the latest cumulative updates for SharePoint Server 2016 and 2019.

3

Restrict access

Implement network-level access controls to limit exposure of SharePoint management interfaces and critical functions to trusted internal IP ranges only, reducing the external attack surface.

4

Monitor for exploitation

Audit SharePoint access logs for unusual activity on administrative endpoints and review account privilege changes that lack corresponding authorized change requests.

Detection Guidance

"To detect potential exploitation of CVE-2026-56164, security teams should monitor IIS logs for unauthenticated requests directed at sensitive SharePoint service endpoints or API calls that typically require administrative permissions. Watch for anomalous privilege escalation events in Windows Security logs and correlate network traffic with known indicators of compromise (IOCs) provided in CISA's BOD 26-04 guidance. Implementing signatures for CWE-306 patterns can help identify attempts to bypass authentication mechanisms."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management