Microsoft called this SharePoint bug 'Moderate.' the NVD says it's a 9.8 — and hackers are already using it

Same vulnerability, two official severity scores that don't agree: Microsoft rates CVE-2026-56164 a 5.3, the National Vulnerability Database a 9.8.…

Aliteq
Priya Nair · Software & Systems Editor

What you need to know

The bug: missing authentication for a critical function (CWE-306) — an unauthenticated attacker can elevate privileges over the network. No login required.

What you need to know

The scores: Microsoft (the CNA) rates it CVSS 5.3 / Moderate; the NVD independently rates it 9.8 / Critical. Same vector on attack, opposite verdict on impact.

What you need to know

Exploited: confirmed as a zero-day in the wild — Microsoft credits its own Detection and Response Team (DART) for the discovery.

What you need to know

Affected: SharePoint Server 2016 Enterprise (before 16.0.5561.1001), 2019 (before 16.0.10417.20175), Subscription Edition (before 16.0.19725.20434).

What you need to know

Fix: the July 14, 2026 security update. Microsoft's AMSI integration offers partial mitigation but is not a substitute for patching.

The 30-second version

CVE-2026-56164 is a missing-authentication flaw in on-prem SharePoint Server (2016, 2019, Subscription Edition) that lets an unauthenticated attacker escalate privileges over the network. Microsoft…

Aliteq

Read the full story

Microsoft called this SharePoint bug 'Moderate.' the NVD says it's a 9.8 — and hackers are already using it

Read the full story on Aliteq