CISA orders three-day patch for exploited Microsoft SharePoint zero-day CVE-2026-56164 unauthenticated RCE all on-prem versions
Every organization running on-premises Microsoft $MSFT SharePoint is urged to patch now. CISA added CVE-2026-56164, a remote privilege-escalation bug needing no login, to its known-exploited list, giving agencies three days to fix it. Attackers steal server keys to plant malware.
US cyber authorities are pressing organizations to harden their Microsoft $MSFT SharePoint servers without delay. CISA has flagged CVE-2026-56164, a privilege-escalation vulnerability that can be exploited remotely and without any login, and added it to its Known Exploited Vulnerabilities catalog. Federal civilian agencies have been given three days to patch under binding directive BOD 26-04. The flaw was fixed in Microsoft's July 2026 Patch Tuesday, but the risk sits with every unpatched on-premises deployment: Subscription Edition, SharePoint 2019 and 2016 are all affected. According to CISA, attackers chain these issues to gain remote code execution, then steal IIS machine keys and use deserialization techniques to keep a foothold and deploy malware. CISA is urging defenders to rotate IIS machine keys, keep SharePoint off the public internet, tighten access to admin interfaces and hunt for signs of intrusion. On-premises SharePoint has become a recurring target this year, with three separate SharePoint flaws now confirmed as exploited zero-days, so any server exposed to the internet should be treated as a priority. Source: CISA, SecurityWeek