Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
| Vendor | Product | Versions |
|---|---|---|
| microsoft | sharepoint_server | 16.0.0, 16.0.0, 16.0.0 |
Updated CVE-2026-56164 severity to CRITICAL due to active wild exploitation despite lower CVSS 5.3 score, corrected CVSS from 8.8 to 5.3 for CVE-2026-56164, added MITRE ATT&CK T1190 (Exploit Public-Facing Application), and clarified that CVE-2026-56164 can be exploited remotely without authentication making it significantly more dangerous than severity rating suggests.
Article introduces newly exploited vulnerability CVE-2026-56164 (elevation-of-privilege, CVSS 5.3, remotely exploitable without authentication) confirmed in CISA KEV catalog; added CWE-269 and MITRE T1548 technique for privilege escalation attacks.
Updated affected versions with specific fixed version numbers and added CISA KEV tag.
Updated description with technical details, added CVE-2026-45659 to tags, and noted the patch was released in late May.
Updated description with more technical detail, added affected versions, and confirmed severity and CVSS score.
Updated exploit availability to true, added CISA KEV tag, and confirmed CVSS score as 8.8.
Updated description with technical details, added affected versions, changed severity to HIGH, updated CVSS estimate to 7.5, and marked exploit as available and actively exploited.
Updated severity to CRITICAL, changed description to include new details, and noted that no exploit is available.
Initial creation