Back to Blog
CVE-2026-56164, CVE-2026-50522: Microsoft SharePoint — Swiss Government Credential Compromise (July 2026)
vulnerabilities

CVE-2026-56164, CVE-2026-50522: Microsoft SharePoint — Swiss Government Credential Compromise (July 2026)

breachwire TeamAug 8, 20262 min read

CVE-2026-56164, CVE-2026-50522 — Microsoft SharePoint

Two high-severity vulnerabilities, CVE-2026-56164 and CVE-2026-50522, affecting Microsoft SharePoint were actively exploited in July 2026. Attackers leveraged these flaws to compromise login credentials for approximately 200 user and technical accounts within the Switzerland Federal Office of Information Technology, Systems and Telecommunication (BIT). No evidence of confidential or sensitive data exfiltration has been reported, but credential exposure presents an ongoing risk. Both CVEs are under active exploitation; patching is critical.

Attack Vector

Attackers targeted unpatched Microsoft SharePoint servers, exploiting CVE-2026-56164 and CVE-2026-50522 to gain unauthorized access. The attack chain enabled the extraction of login credentials from the affected environment. Successful exploitation required network access to vulnerable SharePoint instances. The breach was detected on July 28, 2026, prompting immediate containment actions, including forced password resets and rapid deployment of security patches. No specific indicators of compromise (IOCs) have been disclosed, but credential harvesting and lateral movement are likely.

Who Is at Risk

All organizations running unpatched Microsoft SharePoint servers are at risk, especially those with public-facing or externally accessible deployments. The Switzerland Federal Office of Information Technology, Systems and Telecommunication (BIT) is confirmed affected, with 200 accounts compromised. Other government and enterprise SharePoint environments should be considered high-priority targets until patched.

Patch & Mitigate

  • Patch: Apply Microsoft security updates addressing CVE-2026-56164 and CVE-2026-50522 immediately. Refer to the official Microsoft advisory for exact patch versions and deployment guidance.
  • Workaround: Restrict external access to SharePoint servers and enforce strong authentication where possible until patching is complete.
  • Detect: Review authentication and access logs for anomalous login attempts, credential usage from unusual IP addresses, and signs of lateral movement post-compromise.

MITRE ATT&CK

  • T1190 — Exploit Public-Facing Application: Attackers exploited SharePoint vulnerabilities to gain initial access.
  • T1078 — Valid Accounts: Compromised credentials were used to access internal resources.
  • T1556 — Modify Authentication Process: Password resets and credential changes were required for containment.

Source: https://www.helpnetsecurity.com/2026/08/07/swiss-government-microsoft-sharepoint-vulnerabilities/

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: