THREAT OPS › CVEs › CVE-2026-56164
CVE-2026-56164 — Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
Vulnerability details
- Affected productsSharePoint Server
- KEV remediation due2026-07-17
Exploiting threat actors
- Earth LuscaG1006
Related reporting
- July 2026 CVE Landscaperecordedfuture
- CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilitiestenable
- Microsoft Patches a Record 570 Security Flawskrebs
- [CISA KEV] CVE-2026-56164 — Microsoft SharePoint Server: Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerabilitycisa_kev
- 20th July – Threat Intelligence Reportcheckpoint_research
- Patch Tuesday - July 2026rapid7
- 2026-009: Critical Vulnerabilities in Microsoft SharePointcert_eu
- Microsoft and Adobe Patch Tuesday, July 2026 Security Update Reviewqualys
- Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilitiestalos
- Microsoft security advisory – July 2026 monthly rollup (AV26-698) – Update 3cccs_ca
- Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)tenable
- The July 2026 Security Update Reviewzdi_blog