NopSec.com uses cookies to make interactions with the Company’s Websites easy and meaningful. When you visit one of the Company’s Websites, NopSec.com’s servers send a cookie to your computer. Standing alone, cookies do not personally identify you; they merely recognize your Web browser. Unless you choose to identify yourself to NopSec.com, either by responding to a promotional offer, opening an account, or filling out a Web form (such as a “Contact Us” or a “Free Trial” Web form), you remain anonymous to the Company. Please go to our privacy statement for details.

Microsoft SharePoint Server: CVE-2026-56164

Multi-color grid abstract

What is CVE-2026-56164?

CVE-2026-56164, also known as the Microsoft SharePoint Server Elevation of Privilege Vulnerability, is a critical zero-day privilege escalation flaw affecting self-hosted environments. Discovered during active attacks and patched in July 2026, this vulnerability stems from a severe flaw that allows attackers to bypass core access restrictions entirely.

Key aspects of the vulnerability

Attack Mechanism:
The flaw is caused by a missing authentication check on a critical function within Microsoft Office SharePoint (CWE-306). Because authentication is completely absent for this specific feature, an unauthenticated network-based attacker can send malicious requests directly to an internet-exposed SharePoint instance.

Impact:
Successful exploitation allows an unauthenticated attacker to elevate their privileges on the vulnerable SharePoint host. In real-world attacks, threat actors chain this privilege escalation with post-exploitation techniques, such as stealing Internet Information Services (IIS) machine keys and abusing deserialization weaknesses, to achieve remote code execution (RCE) and establish permanent backdoors.

Mitigation:
Microsoft released patches for CVE-2026-56164 on July 14, 2026, as part of a record-setting Patch Tuesday. The update properly enforces the missing authentication checks on the affected code paths. Enabling the Antimalware Scan Interface (AMSI) in Full Request Body Scan mode provides an additional layer of protection. See the mitigations below for details.

How bad is this?

According to Microsoft and the Cybersecurity and Infrastructure Security Agency (CISA), CVE-2026-56164 has a CVSS v3.1 Base Score of 5.3 (Medium) from the vendor, though NVD/CISA-ADP calculations flag its potential operational impact up to 9.8 (Critical) depending on environment chaining. It is officially categorized under CWE-306: Missing Authentication for Critical Function.

  • Severity: High / Priority (Actively Exploited Zero-Day)
  • No credentials or domain access required
  • Low-complexity, trivial remote exploitation

Who is affected by this?

The vulnerability strictly affects on-premises/self-hosted environments. SharePoint Online is not affected. The following platforms are vulnerable:

Product Affected Versions
Microsoft SharePoint Enterprise Server 2016 All builds prior to July 2026 update
Microsoft SharePoint Server 2019 All builds prior to July 2026 update
Microsoft SharePoint Server Subscription Edition All builds prior to July 2026 update

Critical Operational Note: The patch for this zero-day dropped on July 14, 2026, the exact same day SharePoint Server 2016 and 2019 reached their official End of Extended Support. Organizations running these older legacy deployments must apply this emergency fix immediately, as no future security updates or Extended Security Updates (ESU) are planned.

How is it exploited?

This vulnerability is exploitable remotely over a network by a completely unauthenticated actor. The attacker requires no prior foothold, no user interaction, and zero credentials. By issuing a direct, malformed request to exposed web endpoints, the attacker inherits elevated access permissions on the web application.

How do I protect myself?

Microsoft has released software-specific updates to address this vulnerability. Security teams must follow SharePoint’s unique servicing process to apply the fix; simply installing the standard cumulative Windows OS updates on the underlying host will not remediate the SharePoint farm. If patching cannot happen right away, see the mitigations below.

Mitigating factors?

If patches cannot be deployed immediately, implementing the following defensive measures can blunt the threat surface:

  • Enable AMSI in Full Mode: Ensure your SharePoint servers have the Antimalware Scan Interface integration enabled with the Request Body Scan mode set to “Full” to detect inbound web exploits.
  • Restrict Endpoints: Lock down network access to SharePoint management and web directories, ensuring they are not reachable from untrusted external IP addresses.

Additional Resources

Schedule a Product Demo Today!

See how NopSec's security insights and cyber thread exposure management system platform can organize your security chaos.

New Case Study: When Cyber Risk Is Financial Risk

X