Vulnerability intelligence
CVE-2026-56164
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
5.3
Medium
EPSS — Exploit Probability
27%
Riskier than 98% of all CVEs
Exploitation
Confirmed in the wild
KEV since 2026-07-14
Remediation
Patch available
Federal deadline 2026-07-17
11 articles across 8 outlets · first covered Jul 14, 2026 · latest Jul 22, 2026
Coverage timeline
-
Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attackswww.securityweek.com · Jul 22, 2026
-
Microsoft, SonicWall bugs found; RabbitMQ patches auth flawssecurityonline.info · Jul 15, 2026
-
CISA urges swift patching of SharePoint after zero day exploitswww.securityweek.com · Jul 15, 2026
-
Microsoft patches 622 flaws, fixes three critical zero day bugswww.malwarebytes.com · Jul 15, 2026
-
Patch Tuesday - July 2026www.rapid7.com · Jul 15, 2026
-
Microsoft patches 570 flaws, two zero days actively exploitedsecurityonline.info · Jul 15, 2026
-
Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakeswww.darkreading.com · Jul 14, 2026
-
CISA KEV Flags SharePoint Privilege Escalation Bug CVE-2026-56164www.cisa.gov · Jul 14, 2026
-
CISA adds SharePoint Server flaw CVE‑2026-56164 to KEV listcisa.gov · Jul 14, 2026
-
Microsoft releases record 621 patches as Adobe updates key appswww.thezdi.com · Jul 14, 2026
-
Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Dayswww.securityweek.com · Jul 14, 2026