CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-55164

criticalknown exploitedcovered by 1 sourcefirst seen 2026-07-15
Actively exploited. CVE-2026-55164 is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild, and US federal agencies are required to remediate it under BOD 22-01. Treat patching as urgent.
Number: AL26-017 Date: July 15, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security (Cyber Centre) is also available to provide additional assistance regarding the content of this Alert upon request. Details The Canadian Centre for Cyber Security (Cyber Centre) is aware of critical vulnerabilities affecting Microsoft SharePoint Server. In response to the Microsoft security advisory, released on July 14, 2026 Footnote 1 , the Cyber Centre issued AV26-698 Footnote 2 on July 14, 2026. Tracked as CVE-2026-55164 Footnote 3 , this vulnerability is a Missing Authentication for Critical Function (CWE-306) Footnote 4 vulnerability affecting multiple versions of Microsoft SharePoint Server, that could allow an unauthorized attacker to elevate privileges over a network. Tracked as CVE-2026-55040 Footnote 5 Footnote 6 , this vulnerability is a Weak Authentication (CWE-1390) Footnote 7 vulnerability affecting multiple versions of Microsoft SharePoint Server, that could allow an unauthorized attacker to bypass a security feature over a network. Tracked as CVE-2026-58644 Footnote 8 , this vulnerability is a Deserialization of Untrusted Data (CWE-502) Footnote 9 vulnerability affecting multiple versions of Microsoft SharePoint Server, that could allow an unauthorized attacker to execute code over a network. Microsoft is aware of exploitation of CVE-2026-56164 and other previously released SharePoint related vulnerabilities. CVE-2026-56164 was added to the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog Footnote 10 on July 14, 2026. Suggested actions The Cyber Centre recommends that organizations upgrade affected Microsoft SharePoint instances to a fixed version: Affected prod

CSIRTS triage

What
There are critical vulnerabilities affecting Microsoft SharePoint Server that allow unauthorized access to critical functions.
Who is affected
Deployments of Microsoft SharePoint Server are affected by these vulnerabilities.
Urgency
Remediation is urgent due to active exploitation and the critical severity of the vulnerabilities.
Action
Apply the latest security updates provided by Microsoft.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-55164

Get an email if CVE-2026-55164 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-55164

CVE.org record

CISA KEV catalog

Embed the live status

CVE-2026-55164 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-55164 status](https://www.csirts.com/badge/CVE-2026-55164)](https://www.csirts.com/cve/CVE-2026-55164)