• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-56164: pre-auth privilege elevation in Microsoft SharePoint Server

An unauthenticated attacker can elevate privileges on Microsoft SharePoint Server (CVE-2026-56164). The flaw is a missing authentication for a critical function that allows privilege elevation over the network with no user interaction required. Affected products include SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition in the listed 16.x builds prior to the fixed updates; an attacker needs only network access to reach the vulnerable service.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.01011
CWE
CWE-306
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent: CISA added this CVE to its Known Exploited Vulnerabilities catalog, imposing a federal remediation deadline; prioritize applying the vendor fixes or mitigations immediately for internet-facing SharePoint servers.

What is CVE-2026-56164?

An unauthenticated attacker can elevate privileges on Microsoft SharePoint Server (CVE-2026-56164). The flaw is a missing authentication for a critical function that allows privilege elevation over the network with no user interaction required. Affected products include SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition in the listed 16.x builds prior to the fixed updates; an attacker needs only network access to reach the vulnerable service. The weakness is classified as CWE-306 (Missing Authentication for Critical Function).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft SharePoint Server are affected?

BRANCHAFFECTEDFIXED
Microsoft SharePoint Enterprise Server 2016 16.x16.0.0 – before 16.0.5561.100116.0.5561.1001
Microsoft SharePoint Server 2019 16.x16.0.0 – before 16.0.10417.2017516.0.10417.20175
Microsoft SharePoint Server Subscription Edition 16.x16.0.0 – before 16.0.19725.2043416.0.19725.20434

Is CVE-2026-56164 being exploited?

CISA added CVE-2026-56164 to the Known Exploited Vulnerabilities catalog on 2026-07-14, and US federal agencies were required to remediate it by 2026-07-17. Public exploit code for this vulnerability is available.

How to fix CVE-2026-56164

  1. Apply the vendor updates that fix the issue: 16.0.5561.1001 for Enterprise Server 2016, 16.0.10417.20175 for Server 2019, or 16.0.19725.20434 for Subscription Edition.
  2. If you cannot patch immediately, block or restrict network exposure to SharePoint servers from untrusted networks and VPNs.
  3. Follow Microsoft’s guidance and implement recommended mitigations and monitoring for suspicious activity against SharePoint.
  4. Review logs and telemetry for anomalous privilege elevation attempts and prepare for incident response if indicators are observed.

Frequently asked questions

Is CVE-2026-56164 being actively exploited?

CISA added CVE-2026-56164 to its Known Exploited Vulnerabilities catalog on 2026-07-14 (federal remediation due 2026-07-17), and public exploit code is available.

Which SharePoint Server versions are affected by CVE-2026-56164?

Affected are Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition 16.x builds listed as 16.0.0 through the builds before their respective fixed updates.

Is there a patch for CVE-2026-56164?

Yes. Fixed builds are 16.0.5561.1001 for Enterprise Server 2016, 16.0.10417.20175 for Server 2019, and 16.0.19725.20434 for Subscription Edition.

Does CVE-2026-56164 require authentication?

No. The vulnerability is a missing authentication for a critical function in SharePoint Server and can be exploited by an unauthenticated actor with network access.

References