criticalKEV
CVE-2026-56164
SharePoint Server on-premises remote code execution - actively exploited July 2026, chained for IIS machine-key theft
- Severity
- critical
- Affected product
- Microsoft SharePoint Server
- Affected versions
- Microsoft SharePoint Server all versions before the fix
- CISA KEV
- Listed as a known exploited vulnerability
- Added to NewScan
- 2026-08-06
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Microsoft SharePoint Server appliance and reports this CVE when the detected version falls inside the affected range below.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →