CVE-2026-56164: Microsoft SharePoint Server Missing-Authentication Vulnerability Actively Exploited, Added to CISA KEV
CVE-2026-56164 (TL-2026-1369) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-07-15. It has no confirmed attribution, affects Microsoft SharePoint Enterprise Server 2016, references 5 CVEs (CVE-2026-56164, CVE-2026-56155, CVE-2026-55040), maps to 17 MITRE ATT&CK techniques (T1041, T1053, T1059), and is covered by 9 detection rules and 18 indicators of compromise.
Key facts for TL-2026-1369
- Threat ID
- TL-2026-1369
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-07-15
- Last reviewed
- 2026-07-15
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, education, energy, technology
- Target regions
- North America, Europe, Asia
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in CVE-2026-56164
Malware and tooling: 4L4MD4R, AMSI (Antimalware Scan Interface)
CVE-2026-56164 is a missing-authentication (CWE-306) elevation-of-privilege flaw in on-premises Microsoft SharePoint Server that lets an unauthenticated network attacker escalate privileges with no user interaction. Microsoft confirmed active exploitation and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-07-14, giving federal agencies until 2026-07-17 to remediate under BOD 26-04.
How CVE-2026-56164 works
CVE-2026-56164 is a missing-authentication-for-critical-function vulnerability (CWE-306) in on-premises Microsoft SharePoint Server, disclosed and patched as part of Microsoft's record-breaking July 2026 Patch Tuesday release (622 total CVEs, including 416 Windows flaws). The vulnerability allows an unauthorized, unauthenticated attacker to remotely elevate privileges over the network with low attack complexity and no prior credentials or user interaction, making exploitation reliable and repeatable. NVD rates the flaw 9.8 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), while Microsoft's own scoring is comparatively conservative at 5.3 MEDIUM (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N) — a discrepancy multiple outlets flagged as understating real-world risk given confirmed in-the-wild exploitation. Reporting from BleepingComputer indicates exploitation of the underlying class of SharePoint flaw allows attackers to bypass authentication, achieve remote code execution, and conduct post-exploitation activity including theft of IIS machine keys (used to forge authentication tokens and maintain persistent access) and deployment of malware. Microsoft credited discovery to Mandiant/Google FLARE incident responders and an anonymous researcher, consistent with detection during active-attack incident response rather than proactive research. Affected products are on-premises SharePoint Enterprise Server 2016 (pre-16.0.5561.1001), SharePoint Server 2019 (pre-16.0.10417.20175), and SharePoint Server Subscription Edition (pre-16.0.19725.20434); SharePoint Online is not affected. CVE-2026-56164 was patched and disclosed as exploited in the same release cycle as a second actively-exploited zero-day, CVE-2026-56155 (Active Directory Federation Services elevation of privilege, CVSS 7.8), and alongside a separately-embargoed authentication-bypass/RCE exploit chain (CVE-2026-55040, a JWT validation bypass discovered by Rapid7's Stephen Fewer, whose second chain component remains embargoed until August 2026). CISA's KEV alert also references two other actively-exploited on-premises SharePoint vulnerabilities from earlier in 2026 (CVE-2026-32201, added 2026-04-14, and CVE-2026-45659, added 2026-07-01), with Shadowserver reporting nearly 10,000 internet-exposed SharePoint servers and over 800 still unpatched against those two flaws alone. This continues a well-established pattern: on-premises SharePoint has been a recurring high-value target since the July 2025 'ToolShell' campaign (CVE-2025-49706 auth bypass chained with CVE-2025-49704 deserialization RCE, tracked by MITRE as Campaign C0058), which was exploited by Chinese state-sponsored actors Linen Typhoon and Violet Typhoon and by the Storm-2603 threat actor to deploy 4L4MD4R ransomware, a Mauri870-derived open-source ransomware variant. Microsoft's recommended interim mitigation for CVE-2026-56164 is enabling the Antimalware Scan Interface (AMSI) integration with Request Body Scan set to Full mode; the primary remediation is installing the July 2026 security update. CISA urges hardening beyond patching alone, and directs agencies unable to patch or mitigate to disconnect affected on-premises SharePoint instances from federal networks per BOD 26-04.
MITRE ATT&CK techniques used in TL-2026-1369
Exfiltration
T1041 Exfiltration Over C2 Channel
Persistence
T1053 Scheduled Task/Job; T1505 Server Software Component
Execution
T1059 Command and Scripting Interpreter
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Defense Evasion
T1070 Indicator Removal; T1211 Exploitation for Stealth
Command and Control
T1071 Application Layer Protocol
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery
Initial Access
T1190 Exploit Public-Facing Application
Lateral Movement
T1210 Exploitation of Remote Services
Collection
T1213 Data from Information Repositories
Impact
T1486 Data Encrypted for Impact
Credential Access
Resource Development
Reconnaissance
Affected products and versions in CVE-2026-56164
- Microsoft — SharePoint Enterprise Server 2016
Vulnerable versions: before 16.0.5561.1001
Fixed in: 16.0.5561.1001 and later - Microsoft — SharePoint Server 2019
Vulnerable versions: before 16.0.10417.20175
Fixed in: 16.0.10417.20175 and later - Microsoft — SharePoint Server Subscription Edition
Vulnerable versions: before 16.0.19725.20434
Fixed in: 16.0.19725.20434 and later
Remediation for CVE-2026-56164
Patches
- Microsoft July 2026 Patch Tuesday security update for CVE-2026-56164 (see MSRC update guide)
Immediate actions
- Apply the July 2026 Microsoft security update for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition
- Enable Antimalware Scan Interface (AMSI) integration on all on-premises SharePoint servers and set Request Body Scan mode to Full
- Federal agencies must remediate or disconnect affected instances by 2026-07-17 per CISA BOD 26-04
Workarounds
- If patching is not immediately possible, restrict public/internet access to the SharePoint Server instance
- Discontinue use of the product per vendor instructions if neither patching nor mitigation is feasible
Longer-term hardening
- Deploy EDR/behavioral monitoring on SharePoint front-end and application servers
- Rotate IIS machine keys on all on-premises SharePoint farms following patching
- Restrict internet exposure of on-premises SharePoint Server; place behind authenticated reverse proxy/VPN where feasible
- Track and remediate the broader 2026 SharePoint KEV cluster (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) given nearly 10,000 internet-exposed instances reported by Shadowserver
CVEs associated with CVE-2026-56164
CVE-2026-56164, CVE-2026-56155, CVE-2026-55040, CVE-2026-32201, CVE-2026-45659
Weaknesses (CWE) in CVE-2026-56164
CWE-306
Timeline of CVE-2026-56164
- Prior-generation on-premises SharePoint exploitation ('ToolShell', CVE-2025-49706/CVE-2025-49704/CVE-2025-53770, MITRE Campaign C0058) begins widespread active exploitation, establishing SharePoint as a recurring high-value target.
- Microsoft publishes guidance on disrupting active exploitation of the 2025 on-premises SharePoint ToolShell vulnerabilities, later linked to Storm-2603's deployment of 4L4MD4R ransomware.
- CISA adds a separate actively-exploited on-premises SharePoint vulnerability, CVE-2026-32201, to the KEV catalog.
- CISA adds another actively-exploited SharePoint vulnerability, CVE-2026-45659, to the KEV catalog.
- CISA publishes an alert urging organizations to harden on-premises SharePoint deployments beyond simple patching, referencing the broader 2026 SharePoint KEV cluster.
- CISA adds CVE-2026-56164 to its Known Exploited Vulnerabilities catalog, citing confirmed active exploitation enabling unauthorized access to on-premises SharePoint Server instances.
- Microsoft's July 2026 Patch Tuesday (622 CVEs total) discloses and patches CVE-2026-56164 as an actively-exploited zero-day, alongside actively-exploited CVE-2026-56155 (ADFS) and the embargoed CVE-2026-55040 JWT-bypass RCE chain.
- The Hacker News, BleepingComputer, Help Net Security, and Rapid7 publish analysis detailing the vulnerability's scoring discrepancy (NVD 9.8 vs Microsoft 5.3), IIS machine-key theft risk, and the related ADFS/JWT-bypass flaws.
- Deadline for U.S. federal civilian agencies to remediate or disconnect affected on-premises SharePoint Server instances under CISA Binding Operational Directive 26-04.
Sources cited for CVE-2026-56164
- SharePoint Server Vulnerability Exploited - Cyber Security News
- CVE-2026-56164 Detail - NVD
- Known Exploited Vulnerabilities Catalog - CISA
- CISA Urges SharePoint Hardening After New Exploitations
- Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack - The Hacker News
- CISA warns admins to patch actively exploited SharePoint flaws - BleepingComputer
- AI-driven bug hunting fuels record Microsoft Patch Tuesday - Help Net Security
- Patch Tuesday - July 2026 - Rapid7
- CVE-2026-56164 Security Update Guide - Microsoft Security Response Center
- SharePoint ToolShell Exploitation, Campaign C0058 - MITRE ATT&CK
- Disrupting active exploitation of on-premises SharePoint vulnerabilities - Microsoft Security Blog
Threats related to CVE-2026-56164
- Microsoft July 2026 Patch Tuesday: 570 Flaws Fixed, 3 Zero-Days Including AD FS and SharePoint Privilege Escalation
- Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Including Two Under Active Exploitation (CVE-2026-56155, CVE-2026-56164)
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS and SharePoint (CVE-2026-56155, CVE-2026-56164)
- Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Fixed, Including 2 Actively Exploited Zero-Days (CVE-2026-56164, CVE-2026-56155)
- Microsoft July 2026 Patch Tuesday: Record 622 Flaws Fixed, Two Zero-Days Under Active Exploitation (CVE-2026-56164, CVE-2026-56155)
- July 2026 Patch Tuesday: Microsoft Fixes 622 CVEs Including Three Actively-Targeted Zero-Days (CVE-2026-56155 AD FS EoP, CVE-2026-56164 SharePoint EoP, CVE-2026-50661 BitLocker Bypass)
Detection coverage for TL-2026-1369
As of 2026-07-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1369 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.