CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

AL26-017 - Critical vulnerabilities impacting Microsoft SharePoint Server – CVE-2026-56164, CVE-2026-55040 and CVE-2026-58644

criticalknown exploitedpublic exploitCVE-2026-56164CVE-2026-55040CVE-2026-58644CVE-2026-55164
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Number: AL26-017 Date: July 15, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (Cyber Centre) is also available to provide additional assistance regarding the content of this Alert upon request. Details The Canadian Centre for Cyber Security (Cyber Centre) is aware of critical vulnerabilities affecting Microsoft SharePoint Server. In response to the Microsoft security advisory, released on July 14, 2026 Footnote 1 , the Cyber Centre issued AV26-698 Footnote 2 on July 14, 2026. Tracked as CVE-2026-55164 Footnote 3 , this vulnerability is a Missing Authentication for Critical Function (CWE-306) Footnote 4 vulnerability affecting multiple versions of Microsoft SharePoint Server, that could allow an unauthorized attacker to elevate privileges over a network. Tracked as CVE-2026-55040 Footnote 5 Footnote 6 , this vulnerability is a Weak Authentication (CWE-1390) Footnote 7 vulnerability affecting multiple versions of Microsoft SharePoint Server, that could allow an unauthorized attacker to bypass a security feature over a network. Tracked as CVE-2026-58644 Footnote 8 , this vulnerability is a Deserialization of Untrusted Data (CWE-502) Footnote 9 vulnerability affecting multiple versions of Microsoft SharePoint Server, that could allow an unauthorized attacker to execute code over a network. Microsoft is aware of exploitation of CVE-2026-56164 and other previously released SharePoint related vulnerabilities. CVE-2026-56164 was added to the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog Footnote 10 on July 14, 2026. Suggested actions The Cyber Centre recommends that organizations upgrade affected Microsoft SharePoint instances to a fixed version: Affected prod

CSIRTS triage

What
There are critical vulnerabilities affecting Microsoft SharePoint Server that allow unauthorized access to critical functions.
Who is affected
Deployments of Microsoft SharePoint Server are affected by these vulnerabilities.
Urgency
Remediation is urgent due to active exploitation and the critical severity of the vulnerabilities.
Action
Apply the latest security updates provided by Microsoft.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch SharePoint Server

Get an email when a new SharePoint Server advisory drops — max one per day, one-click unsubscribe.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
critical
Published
2026-07-15
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://cyber.gc.ca/en/alerts-advisories/al26-017-critical-vulnerabilities-impacting-microsoft-sharepoint-server-cve-2026-56164-cve-2026-55040-cve-2026-58644

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-56164coverage & exploitation statusNVD · CVE.org
CVE-2026-55040coverage & exploitation statusNVD · CVE.org
CVE-2026-58644coverage & exploitation statusNVD · CVE.org
CVE-2026-55164coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Canadian Centre for Cyber Security