VDB

CVE-2026-56164

CVE-2026-56164 PUBLISHED KEV CVSS 8.399999618530273 HIGH

On July 14, 2026, Microsoft published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following products: .NET 10.0 installed on Linux .NET 10.0 installed on Mac OS .NET 10.0 installed on Windows .NET 8.0 installed on Linux .NET 8.0 installed on Mac OS .NET 8.0 installed on Windows .NET 9.0 installed on Linux .NET 9.0 installed on Mac OS .NET 9.0 installed on Windows Age of Empires II: Definitive Edition Game Azure Active Directory Azure CycleCloud 8.9.1 Azure Monitor Agent Metrics Extension Azure Open AI Azure Spring Apps Azure Synapse Fabric Data Warehouse GitHub Copilot Plugin for JetBrains IDEs Microsoft .NET Framework Microsoft .NET Framework 3.5 Microsoft .NET Framework 4.8.1 Microsoft 365 Apps Microsoft 365 Apps for Enterprise Microsoft 365 Copilot Microsoft 365 Copilot for Android Microsoft 365 Copilot for iOS Microsoft Bing Search for iOS Microsoft Defender for Endpoint for Mac Microsoft Dynamics NAV 2018 Microsoft Edge (Chromium-based) Microsoft Entra Provisioning Service Microsoft Excel 2016 Microsoft Exchange Online Microsoft Exchange Server 2016 Microsoft Exchange Server 2019 Microsoft Exchange Server Subscription Edition RTM Microsoft Malware Protection Engine Microsoft Office 2016 Microsoft Office 2019 Microsoft Office 365 for Mac Microsoft Office LTSC 2021 Microsoft Office LTSC 2024 Microsoft Office LTSC for Mac 2021 Microsoft Office LTSC for Mac 2024 Microsoft Office for Android Microsoft PC Manager Microsoft PowerPoint 2016 Microsoft SQL Server 2016 Microsoft SQL Server 2017 Microsoft SQL Server 2019 Microsoft SQL Server 2022 Microsoft SQL Server 2025 Microsoft SharePoint Enterprise Server 2016 Microsoft SharePoint Server 2019 Microsoft SharePoint Server Subscription Edition Microsoft Surface Go 2 Microsoft Surface Go 3 Microsoft Surface Hub Microsoft Surface Hub 2S Microsoft Surface Hub 3 Microsoft Surface Laptop Go Microsoft Surface Laptop Go 2 Microsoft Surface Laptop Go 3 Microsoft Surface Pro 7+ Microsoft Surface Pro 8 Microsoft Visual Studio 2022 Microsoft Visual Studio 2026 Microsoft Word 2016 AspNet.OData AspNetCore.OData Minecraft Bedrock Dedicated Server Office Online Server Power BI Report Server Surface Laptop 4 with AMD Processor Surface Laptop 4 with Intel Processor Surface Windows Dev Kit Visual Studio Code Windows 10 Windows 11 Windows 11 Version Windows Admin Center Windows Remote Help Windows Server 2012 Windows Server 2012 R2 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025 Windows Subsystem for Linux (WSL2) Windows Terminal for Windows 10 Windows Terminal for Windows 11 Microsoft has indicated that CVE-2026-56164 and CVE-2026-56155 are being exploited. On July 14, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-56164 and CVE-2026-56155 to their Known Exploited Vulnerabilities (KEV) Database. Update 1 On July 16, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-58644 to their Known Exploited Vulnerabilities (KEV) Database. Update 2 Open-source reporting indicates that CVE-2026-50522 is being exploited in the wild. Update 3 On July 22, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-50522 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.

Risk Scores

CVSS 4.0
8.399999618530273
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
UnauthorizedUnauthorized authentication attempts
MicrosoftWindows Server 2019
ActivitésActivités d'élévation des privilèges imprévues.
MicrosoftWindows Server 2022
VisualVisual Studio Code
MicrosoftMicrosoft Bing Search for iOS
MicrosoftMicrosoft Dynamics NAV 2018
MicrosoftMicrosoft Defender for Endpoint for Mac
MicrosoftMicrosoft PC Manager
MicrosoftUse or upgrade to supported versions of on-premises Microsoft SharePoint Server
MicrosoftMicrosoft Exchange Online
MicrosoftMicrosoft Surface Go 3
MicrosoftMicrosoft Surface Laptop Go 3
Microsoft.NET 10.0 installed on Windows
.NET.NET 8.0 installed on Mac OS
MicrosoftMicrosoft Word 2016
MicrosoftMicrosoft Surface Hub
isolerisoler les applications Web.
MicrosoftMicrosoft Visual Studio 2026
ActivitésActivités suspectes liées à l'accès aux clés machine IIS.

…and 104 more

Timeline

  • Jul 14, 2026 CISA KEV Added
  • Jul 14, 2026 PoC Published
  • Jul 14, 2026 CVE Published
  • Jul 15, 2026 Coalition ESS Score
  • Jul 16, 2026 Security Advisory
  • Aug 6, 2026 Security Advisory
  • Aug 7, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›