CVE-2026-56164 is a privilege escalation vulnerability in Microsoft SharePoint Server with active exploitation. Patch affected versions immediately.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| sharepoint_server | * | 16.0.19725.20434 | vulnerable |
| sharepoint_server | 2016 | 2016 | vulnerable |
| sharepoint_server | 2019 | 2019 | vulnerable |
Download and install the security updates provided by Microsoft via the MSRC Update Guide for your specific version of SharePoint Server to address the missing authentication flaw.
Ensure all SharePoint Server instances are updated beyond version 16.0.19725.20434. This includes applying the latest cumulative updates for SharePoint Server 2016 and 2019.
Implement network-level access controls to limit exposure of SharePoint management interfaces and critical functions to trusted internal IP ranges only, reducing the external attack surface.
Audit SharePoint access logs for unusual activity on administrative endpoints and review account privilege changes that lack corresponding authorized change requests.
"To detect potential exploitation of CVE-2026-56164, security teams should monitor IIS logs for unauthenticated requests directed at sensitive SharePoint service endpoints or API calls that typically require administrative permissions. Watch for anomalous privilege escalation events in Windows Security logs and correlate network traffic with known indicators of compromise (IOCs) provided in CISA's BOD 26-04 guidance. Implementing signatures for CWE-306 patterns can help identify attempts to bypass authentication mechanisms."
Experience superior visibility and a simpler approach to cyber risk management