LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-56164: Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 14, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 17, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-56164 to its Known Exploited Vulnerabilities catalog on Jul 14, 2026, with a federal patch deadline of Jul 17, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.

Microsoft SharePoint Server is affected by a missing authentication for critical function vulnerability. An unauthorized attacker can use it to elevate privileges over a network. This matters because the flaw allows network-based privilege escalation in environments where SharePoint handles sensitive content and access controls.

How it works

The weakness is categorized as CWE-306, missing authentication for critical function. In this class of vulnerability, a server component fails to verify that a caller is authorized before performing an action that should require authentication.

An attacker reaches the affected function over the network and issues requests that the server processes without first confirming identity or permissions, resulting in privilege elevation.

Am I affected? How to find it in your systems

Microsoft SharePoint Server typically runs on-premises as part of intranet or collaboration deployments. Inventory all SharePoint Server installations through configuration management databases, server asset lists, and application discovery scans.

How to remediate

Apply the vendor update named in the advisory as the primary remediation step. Follow all instructions provided by Microsoft for installing and verifying the fix.

If you can't patch immediately

Until the update can be applied, reduce exposure through network segmentation that limits access to SharePoint servers from untrusted sources. Consider web application firewall rules that enforce authentication on the affected function paths where feasible.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to breaches that expose account data or content stored in SharePoint. Run a free exposure scan of your email addresses against known breach data to check for prior incidents involving your organization.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · SharePoint Server
WeaknessCWE-306
Added to CISA KEVJul 14, 2026
Federal patch deadlineJul 17, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities