CRITICAL #1 SharePoint Server Zero-Day CVE-2026-56164 Added to CISA KEV
Microsoft's July 14 Patch Tuesday disclosed CVE-2026-56164, a missing-authentication flaw in on-premises SharePoint Server 2016, 2019, and Subscription Edition allowing an unauthenticated attacker to escalate privileges over the network. Attackers are chaining it with older SharePoint weaknesses to steal IIS machine keys and establish persistence. CISA added it to the KEV catalog the same day.
Federal civilian agencies were assigned a July 17 remediation deadline. Under NIST 800-171 this maps to 3.14.1 (flaw remediation) and 3.4.1 (baseline configuration); machine-key theft implicates 3.5.x identity controls and demands IIS key-rotation evidence for CMMC assessors.
