← Back to Feed
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
CVE-2026-56164
July 31, 2026 · CISA · Severity: CRITICAL
Microsoft SharePoint Server: Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
Vendor: Microsoft
Product: SharePoint Server
CISA Date Added: 2026-07-14
CVE: CVE-2026-56164
This vulnerability is actively exploited in the wild according to CISA Known Exploited Vulnerabilities catalog.
Key Takeaways
- CVE-2026-56164 is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog.
- The vulnerability involves privilege escalation or authentication bypass, granting unauthorized access to sensitive functions.
- CISA BOD 26-04 requires remediation within the specified due date — apply vendor mitigations promptly.
- Active exploitation has been confirmed, increasing urgency for patching across all affected deployments.
- Microsoft SharePoint Server: Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.