Our takeAnother SharePoint deserialization RCE, critical severity. Not one of the three CVEs CISA says are under active exploitation (32201, 45659, 56164) — patch it anyway, on-prem SharePoint is now averaging multiple deserialization bugs per advisory cycle.Cyber Resilience desk
Sources (12)
- cisa_advisories · cisa_advisories
- cisa_advisories · cisa_advisories
- nvd_recent · nvd_recent
- nvd_recent · nvd_recent
- nvd_recent · nvd_recent
- nvd_recent · nvd_recent
- nvd_recent · nvd_recent
- cccs · cccs
- bleeping · bleeping
- securityweek · securityweek
- securityweek · securityweek
- bleeping · bleeping
What this means for you — Security leader:Patch all on-prem SharePoint (Subscription Edition, 2019, 2016) against CVE-2026-56164 and related deserialization/auth flaws now; confirm which of your instances are internet-facing and check CISA's KEV catalog for the actively-exploited set (32201, 45659, 56164).
What this means for you — Lean IT orgs:If you run SharePoint on your own server (not Microsoft 365 cloud), get your IT provider to patch it immediately — attackers are actively breaking into unpatched on-prem SharePoint servers right now.
What this means for you — MSP:Inventory every client running on-prem SharePoint Server (any edition); prioritize patching CVE-2026-56164 and the other actively exploited CVEs across all tenants before addressing lower-severity SharePoint CVEs in this batch.
What this means for you — Researcher:Multiple SharePoint deserialization/auth CVEs landed together (50522, 58644, 55040, 56164) alongside CISA's advisory naming a different exploited set (32201, 45659, 56164) — worth mapping overlap and checking if 50522/58644 share a root cause with the confirmed-exploited chain.