AL26-017 - Critical vulnerabilities impacting Microsoft SharePoint Server – CVE-2026-56164, CVE-2026-55040 and CVE-2026-58644
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Number: AL26-017 Date: July 15, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (Cyber Centre) is also available to provide additional assistance regarding the content of this Alert upon request. Details The Canadian Centre for Cyber Security (Cyber Centre) is aware of critical vulnerabilities affecting Microsoft SharePoint Server. In response to the Microsoft security advisory, released on July 14, 2026 Footnote 1 , the Cyber Centre issued AV26-698 Footnote 2 on July 14, 2026. Tracked as CVE-2026-55164 Footnote 3 , this vulnerability is a Missing Authentication for Critical Function (CWE-306) Footnote 4 vulnerability affecting multiple versions of Microsoft SharePoint Server, that could allow an unauthorized attacker to elevate privileges over a network. Tracked as CVE-2026-55040 Footnote 5 Footnote 6 , this vulnerability is a Weak Authentication (CWE-1390) Footnote 7 vulnerability affecting multiple versions of Microsoft SharePoint Server, that could allow an unauthorized attacker to bypass a security feature over a network. Tracked as CVE-2026-58644 Footnote 8 , this vulnerability is a Deserialization of Untrusted Data (CWE-502) Footnote 9 vulnerability affecting multiple versions of Microsoft SharePoint Server, that could allow an unauthorized attacker to execute code over a network. Microsoft is aware of exploitation of CVE-2026-56164 and other previously released SharePoint related vulnerabilities. CVE-2026-56164 was added to the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog Footnote 10 on July 14, 2026. Suggested actions The Cyber Centre recommends that organizations upgrade affected Microsoft SharePoint instances to a fixed version: Affected prod
CSIRTS triage
- What
- There are critical vulnerabilities affecting Microsoft SharePoint Server that allow unauthorized access to critical functions.
- Who is affected
- Deployments of Microsoft SharePoint Server are affected by these vulnerabilities.
- Urgency
- Remediation is urgent due to active exploitation and the critical severity of the vulnerabilities.
- Action
- Apply the latest security updates provided by Microsoft.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch SharePoint Server
Get an email when a new SharePoint Server advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/al26-017-critical-vulnerabilities-impacting-microsoft-sharepoint-server-cve-2026-56164-cve-2026-55040-cve-2026-58644
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-56164Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 97% of all scored CVEs.
- Exploitation confirmedCVE-2026-55040Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 74% of all scored CVEs.
- Exploitation confirmedCVE-2026-58644Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 93% of all scored CVEs.
- Exploitation confirmedCVE-2026-55164Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-56164 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-55040 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58644 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-55164 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedSecurity Alert: [Updated] Microsoft Releases July 2026 Security Updatesjpcert
- criticalexploitedMicrosoft security advisory – July 2026 monthly rollup (AV26-698) – Update 3cccs
- criticalexploited2026-009: Critical Vulnerabilities in Microsoft SharePointcert-eu
- unknownexploitedMultiple vulnerabilities in Microsoft Sharepoint (July 22, 2026)cert-fr-alerte
- unknownexploitedNCSC-2026-0237 [1.02] [H/H] Vulnerabilities Fixed in Microsoft Officencsc-nl
- unknownexploitedNCSC-2026-0237 [1.01] [H/H] Vulnerabilities fixed in Microsoft Officencsc-nl
- highexploitedCISA Adds Three Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-58644: Microsoft SharePoint Deserialization of Untrusted Data Vulnerabilitycisa-kev
- unknownMicrosoft Monthly Security Update (July 2026)hkcert
- unknownMultiple vulnerabilities in Microsoft products (July 15, 2026)cert-fr-avis
- unknownexploitedNCSC-2026-0237 [1.00] [M/H] Vulnerabilities fixed in Microsoft Officencsc-nl
- criticalCVE-2026-55040: Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a…nvd
More from Canadian Centre for Cyber Security
- unknownGoogle security advisory (AV26-768)2026-07-31
- unknownRails security advisory (AV26-767)2026-07-31
- unknownSolarWinds security advisory (AV26-766)2026-07-31
- unknownGladinet security advisory (AV26-765)2026-07-30
- unknownPHP Group security advisory (AV26-764)2026-07-30