Active exploitation raises the priority
Microsoft lists CVE-2026-56164 as actively exploited. The vulnerability affects on-premises deployments of SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. Missing authentication for a critical function allows an unauthenticated attacker to elevate privileges over the network. The attack requires neither user interaction nor special preconditions.
The CVSS base score of 5.3 and “Moderate” severity should not delay remediation. For internet-facing farms and those reachable from corporate networks, the confirmed exploitation status is the decisive factor. SharePoint Online is not affected by this on-premises advisory.
These farm builds close the gap
The security updates released on July 14, 2026 must be installed on every SharePoint server in the farm:
- SharePoint Server 2016: KB5002891 and language-dependent package KB5002892, build
16.0.5561.1001. - SharePoint Server 2019: KB5002883 and language-dependent package KB5002885, build
16.0.10417.20175. - SharePoint Server Subscription Edition: KB5002882, build
16.0.19725.20434.
For SharePoint 2016 and 2019, both the language-independent and language-dependent packages are required even on English installations for a fully updated farm. After installation, the SharePoint Products Configuration Wizard or PSConfig must finish successfully on every farm server. Teams should then verify the build level, farm status, Search service, workflows, and published web applications.
Review the version-specific notes for each KB before the maintenance window. Farms using SharePoint Workflow Manager must install KB5002799 before the SharePoint update. The July packages also document repeated sign-ins in multi-WFE farms using Trusted Provider or Forms Authentication, an Office Online Server issue on SharePoint 2016, and an additional post-PSConfig step for Subscription Edition. Include these points in pilot, rollback, and functional testing; do not disable protection settings as a quick fix.
AMSI complements the patch but does not replace it. The SharePoint integration with a compatible antimalware provider must actively scan requests. Microsoft's additional Request Body Scan: Full Mode mitigation is available only in SharePoint Server Subscription Edition 25H1 and later; on those farms it should be enabled and tested in a controlled manner for every relevant web application.
2016 and 2019 now need a migration path
SharePoint Server 2016 and 2019 reached end of support in July 2026. The July patch is the immediate safeguard, not a sustainable operating strategy for the coming months. Continued use without a supported upgrade path creates a risk that the next vulnerability cannot be reliably remediated. On-premises farms should move to SharePoint Server Subscription Edition; farms no longer required should be decommissioned in a controlled process.
If an internet-facing farm remained unpatched after July 14, updating alone is insufficient. Preserve IIS, ULS, Windows, and security telemetry and review it for unexpected access, configuration changes, new accounts, and modified content. Treat anomalies as an incident rather than merely restarting the farm.
The immediate check: record the build on every farm server, install all missing July packages, complete PSConfig, and set a firm migration or retirement deadline for SharePoint 2016 or 2019.
