// Darksteel Insights · 2026-07-29
Critical SharePoint Vulnerability Demands Immediate Action for SMBs
A new SharePoint vulnerability is being exploited in the wild. SMBs must patch now to avoid potential breaches.
- CVE-2026-56164 is a critical SharePoint vulnerability being actively exploited.
- SMBs using SharePoint Server are at risk and should apply patches immediately.
- Apply the Microsoft patch by July 17, 2026, to ensure protection.
- Review logs for unusual activity to detect potential compromise.
What is CVE-2026-56164 and why is it a problem?
CVE-2026-56164 is a flaw in Microsoft SharePoint Server that allows attackers to access and manipulate data in SharePoint without needing to be authenticated. This is a 'missing authentication for critical function' vulnerability, meaning that certain actions that should require login access can be bypassed entirely.
SharePoint is commonly used to store and manage sensitive business data, such as documents, spreadsheets, and internal communications. If an attacker can access these resources without proper authentication, they could steal, alter, or delete data, or use it as a gateway to infiltrate other parts of your network.
CISA added this vulnerability to their Known Exploited Vulnerabilities (KEV) list on July 14, 2026, confirming that it is already being used in real-world attacks. This is a clear warning that businesses need to act now.
How does this affect small and mid-sized businesses?
If your business uses SharePoint Server — even if it's only for internal use — you are at risk. Many SMBs rely on SharePoint for document management, project tracking, and team collaboration. If this vulnerability is exploited, attackers could access your data without needing any credentials.
The flaw is particularly concerning because it allows remote exploitation. This means attackers can target your system from anywhere in the world, without needing any user interaction or social engineering tactics.
Even if you're unsure whether SharePoint is in use, it's worth confirming with your IT team or managed service provider. If it's running and unpatched, it could become a serious security risk.
What should you do this week to protect your business?
The most important action is to apply the Microsoft patch for CVE-2026-56164 as soon as possible. Microsoft has released a fix for this vulnerability, and CISA has set a deadline of July 17, 2026, for systems to be patched. This is a best practice for all SMBs, regardless of federal requirements.
If you're using SharePoint Server on-premises, ensure that your IT team or managed service provider applies the latest security updates. If you're using SharePoint Online (part of Microsoft 365), Microsoft has already applied the patch in the cloud, so no action is needed.
In addition to patching, review your SharePoint configuration to ensure it's not unnecessarily exposed. If it is, consider restricting access to internal users only. This will reduce the risk of external attacks.
Lastly, ensure your team is aware of the vulnerability and the steps you're taking to address it. This is a good opportunity to reinforce the importance of regular patching and security updates.
How can you tell if your system was already compromised?
If you suspect your SharePoint environment has been compromised, the first step is to review system logs for any unusual activity. Look for signs of unauthorized access, such as unexpected file changes or access to sensitive data.
You can use Microsoft's logging and monitoring tools to detect anomalies. If you're not sure how to do this, consider reaching out to a cybersecurity professional or your managed service provider for help.
If you find evidence of a breach, act quickly. Isolate the affected system, change all related passwords, and consider conducting a full security assessment to determine the extent of the damage. It's also a good idea to notify your legal and compliance teams if necessary.
Not sure whether your environment is exposed? That is exactly what our Vulnerability Management service is built to surface. Talk to us.
Frequently asked questions
Is this vulnerability only a problem for large enterprises?
What if I'm using SharePoint Online instead of on-premises?
Can I ignore this if I don't use SharePoint?
What if I can't patch right away?
Source (public domain): CISA