16 July 2026
Reference: CVE-2026-56164
1. What is being reported?
The report highlights a flaw in Microsoft SharePoint Server where a critical function does not properly check if a user is authorised. This means someone could connect to the system remotely and gain more access rights than they should have, potentially allowing them to control or damage the system.
2. What this means in plain English
For a small organisation, this means that if you use Microsoft SharePoint Server and it is connected to the internet or your network, attackers could exploit this flaw to access sensitive information or disrupt your operations without needing proper login credentials.
3. Could this affect a small business?
Small businesses or charities using Microsoft SharePoint Server could be affected, especially if the server is accessible over the internet or not properly secured. Organisations not using SharePoint Server or only using cloud-based Microsoft services without this server are less likely to be affected.
4. What to do now
- Check if your organisation uses Microsoft SharePoint Server and identify where it is installed.
- Contact your IT provider or software supplier to confirm if the server is vulnerable and ask for guidance on applying the latest security updates or mitigations.
- Apply all recommended patches or mitigations from Microsoft as soon as possible to reduce the risk of exploitation.
- Review your SharePoint Server’s internet exposure and restrict access where possible to trusted users only.
5. Ask your IT provider
Can you confirm if our Microsoft SharePoint Server is affected by the CVE-2026-56164 vulnerability, and have all necessary security updates or mitigations been applied?
6. Bottom line
If you use Microsoft SharePoint Server, act quickly to ensure it is updated and secure to prevent attackers from gaining unauthorised access.
Information based on CISA KEV, NVD and reputable security reports.