← All CVEs NewScan detects
criticalKEV

CVE-2026-56164

SharePoint Server on-premises remote code execution - actively exploited July 2026, chained for IIS machine-key theft

Severity
critical
Affected product
Microsoft SharePoint Server
Affected versions
Microsoft SharePoint Server all versions before the fix
CISA KEV
Listed as a known exploited vulnerability
Added to NewScan
2026-08-06
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the Microsoft SharePoint Server appliance and reports this CVE when the detected version falls inside the affected range below.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →