Skip to content
Data Breach

CISA Warns of Microsoft SharePoint Server Vulnerability Actively Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-56164, to its Known Exploited Vulnerabilities catalog due to confirmed active exploitation. This flaw affects on-premises deployments of Microsoft ShareP...

· Jul 15, 2026 · 3 min read · 👁 1 views
CISA Warns of Microsoft SharePoint Server Vulnerability Actively Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-56164, to its Known Exploited Vulnerabilities catalog due to confirmed active exploitation.

This flaw affects on-premises deployments of Microsoft SharePoint Server and allows an unauthenticated attacker to remotely elevate their privileges.

CVE-2026-56164 is classified as a missing-authentication vulnerability affecting critical functions in Microsoft SharePoint Server.

It corresponds to CWE-306, a weakness category involving systems that fail to enforce authentication before granting access to security-sensitive functions.

SharePoint Server Vulnerability Exploited

An attacker does not need valid SharePoint credentials to exploit this vulnerability. According to CISA’s advisory, successful exploitation could enable an unauthorized attacker to gain elevated privileges over a network.

With elevated privileges, attackers can gain greater control over a SharePoint environment, potentially allowing them to access sensitive documents, modify content, create accounts, or move laterally across connected systems.

CISA added this flaw to its Known Exploited Vulnerabilities catalog on July 14, 2026, indicating that the agency has evidence of its exploitation in real-world attacks.

They set a remediation deadline of July 17, 2026, giving federal civilian executive branch agencies only three days to address the issue. The inclusion of this vulnerability in the catalog does not confirm its use in ransomware operations.

CISA currently categorizes ransomware campaign usage as unknown. However, internet-facing SharePoint servers remain high-value targets, as they often contain internal files, business workflows, identity integrations, and connections to other enterprise services.

Organizations using Microsoft SharePoint Server should immediately review Microsoft’s security guidance and implement all available fixes or mitigations.

Security teams should prioritize addressing externally accessible SharePoint instances, as they present the most direct attack surface.

CISA has advised stakeholders to follow vendor instructions and comply with Binding Operational Directive BOD 26-04, which prioritizes security updates according to risk.

Agencies and organizations should also assess whether individual SharePoint assets are exposed to the internet and ensure that remediation actions meet applicable patching deadlines.

If mitigations are unavailable, CISA recommends discontinuing use of the affected product. For cloud-hosted services, organizations should adhere to the relevant BOD 26-04 guidance and confirm responsibilities with their service provider.

Defenders should conduct threat hunting and forensic triage on SharePoint servers, particularly those exposed to the internet.

Teams should review authentication records, web server logs, SharePoint audit events, changes to administrative accounts, suspicious process execution, unexpected scheduled tasks, and unusual outbound network connections.

Organizations should also look for newly created privileged users, unauthorized changes to permissions, web shells, and abnormal access to SharePoint document libraries.

Because exploitation can lead to privilege escalation, incident responders should assume that a compromised SharePoint server may grant attackers access to broader network resources. CISA’s July 17 deadline emphasizes the urgency of addressing this vulnerability.

Organizations that cannot patch immediately should minimize exposure by restricting public access, enforcing network segmentation, closely monitoring server activity, and preparing to isolate affected SharePoint systems if signs of compromise arise.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Related Articles

Recommended for you