Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4357 articles · 196326 vulns · 36/41 feeds (7d)
← Back to list
5.3
CVE-2026-56164KEVEXPLOITEDPATCHED
microsoft · sharepoint_server

Microsoft SharePoint Server Elevation of Privilege Vulnerability

Description

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

Affected Products

VendorProductVersions
microsoftsharepoint_server16.0.0, 16.0.0, 16.0.0

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164(vendor-advisory, patch)

Related News (21 articles)

Tier B
JPCERT/CC
Security Alert: Microsoft Releases July 2026 Security Updates
→ No new info (linked only)
Tier D
Help Net Security16d ago
200 accounts compromised in Swiss government’s Microsoft SharePoint breach
→ No new info (linked only)
Tier D
BleepingComputer17d ago
Swiss government SharePoint breach compromised 200 accounts
→ No new info (linked only)
Tier D
Help Net Security28d ago
Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached
→ No new info (linked only)
Tier B
CERT-FR35d ago
Bulletin d'actualité CERTFR-2026-ACT-031 (20 juillet 2026)
→ No new info (linked only)
Tier D
Help Net Security35d ago
Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs
→ No new info (linked only)
Tier D
SecurityWeek37d ago
Fresh SharePoint Vulnerability Exploited Soon After Disclosure
→ No new info (linked only)
Tier E
Hacker News38d ago
Microsoft's July 2026 Patch Tuesday fixes 622 CVEs, 2 exploited zero-days
→ No new info (linked only)
Tier D
CSO Online38d ago
CISA urges immediate SharePoint hardening as exploits mount
→ No new info (linked only)
Tier B
CCCS Canada39d ago
AL26-017 - Critical vulnerabilities impacting Microsoft SharePoint Server – CVE-2026-56164, CVE-2026-55040 and CVE-2026-58644
→ No new info (linked only)
Tier D
SecurityWeek39d ago
CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities
→ No new info (linked only)
Tier D
The Record39d ago
Microsoft smashes Patch Tuesday record for second successive month
→ No new info (linked only)
Tier D
Help Net Security39d ago
AI-driven bug hunting fuels record Microsoft Patch Tuesday
→ No new info (linked only)
Tier D
BleepingComputer39d ago
CISA warns admins to patch actively exploited SharePoint flaws
→ No new info (linked only)
Tier D
Heise Security39d ago
Microsoft-Patchday: Neuer Rekord mit 622 gefixten Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR40d ago
Multiples vulnérabilités dans les produits Microsoft (15 juillet 2026)
→ No new info (linked only)
Tier C
Cisco Talos40d ago
Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
→ No new info (linked only)
Tier D
The Hacker News40d ago
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
→ No new info (linked only)
Tier B
CCCS Canada40d ago
Microsoft security advisory – July 2026 monthly rollup (AV26-698)
→ No new info (linked only)
Tier C
VulDB40d ago
CVE-2026-56164 | Microsoft SharePoint Server Critical Function missing authentication
→ No new info (linked only)
Tier C
CrowdStrike Blog41d ago
July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days
→ No new info (linked only)
CVSS 3.15.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:F/RL:O/RC:C
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
16.0.5561.1001
CWECWE-306
PublishedJul 14, 2026
Last enriched38d agov7
Tags
elevation of privilegeremote code executionzero-dayprivilege escalationweak authenticationdeserializationcisa-kevactively exploited
Trending Score15
Source articles21
Independent14
Info Completeness12/14
Missing: epss, iocs

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-69836EXPKEV
Microsoft Entra ID Remote Code Execution Vulnerability
Trending: 129
CRITICALCVE-2026-55040EXPKEV
Microsoft SharePoint Server Security Feature Bypass Vulnerability
Trending: 87
CRITICALCVE-2026-50522EXPKEV
Microsoft SharePoint Remote Code Execution Vulnerability
Trending: 80
HIGHCVE-2026-68820EXPKEV
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Trending: 73
HIGHCVE-2026-45586EXPKEV
Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability
Trending: 65

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Added to CISA KEV
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: description, severity
Jul 14, 2026
Updated: patchAvailable, exploitAvailable, severity, tags
Jul 15, 2026
Updated: affectedVersions, cweIds, tags
Jul 15, 2026
Updated: affectedVersions, severity, cweIds, patchAvailable, tags
Jul 15, 2026
Updated: tags
Jul 16, 2026
Updated: affectedVersions, mitreAttack
Jul 16, 2026
Actively Exploited
Aug 20, 2026
Exploit Available
Aug 20, 2026
Patch Available
Aug 20, 2026

Version History

v7
Last enriched 38d ago
v7Tier E38d ago

Added detailed technical context from real-world incident discovery by Mandiant/Google FLARE, clarified affected SharePoint versions (2016, 2019, Subscription Edition), added MITRE ATT&CK technique T1190 (Exploit Public-Facing Application), and included interim mitigation guidance (AMSI Full Request Body Scan).

affectedVersionsmitreAttack
via Hacker News
v6Tier D38d ago

Enhanced description with explicit confirmation of remote exploitation without authentication and added CISA KEV catalog tag to reflect confirmed active exploitation.

tags
via CSO Online
v5Tier B39d ago

Updated affected versions, severity to HIGH, added new CWEs, and provided fixed version numbers.

affectedVersionsseveritycweIdspatchAvailabletags
via CCCS Canada
v4Tier D39d ago

Updated severity to CRITICAL, added affected versions, new CWEs, and included the patch available date.

affectedVersionscweIdstags
via SecurityWeek
v3Tier B39d ago

Updated severity to HIGH, marked exploit as available, and added new tags related to the vulnerability.

patchAvailableexploitAvailableseveritytags
via JPCERT/CC
v2Tier C40d ago

Updated severity to CRITICAL, changed description for more technical detail, and noted that no exploit is available.

descriptionseverity
via VulDB
v140d ago

Initial creation