Call or Text - 
Orlando & Central Florida:
407-554-5534
Naples & Southwest Florida:
239-653-0252
cybernetic_logo_white
Schedule a Free Consultation

On-Premises SharePoint Is Under Active Attack: What Small Businesses Should Check Now

08/04/2026
2149445127(1)

A Security Warning That Does Not Affect Every SharePoint User

Microsoft released a security update on July 14, 2026, for a vulnerability identified as CVE-2026-56164. The vulnerability affects supported versions of Microsoft SharePoint Server, the version of SharePoint that an organization runs on its own server infrastructure.

According to the Center for Internet Security, Microsoft reported that the vulnerability had already been exploited in real attacks. The issue was also added to the federal Known Exploited Vulnerabilities catalog.

That makes this more than a routine software update. Businesses operating an affected SharePoint Server should confirm that the appropriate update has been installed and that the server has been reviewed for possible exposure.

However, there is an important distinction: this warning concerns on-premises SharePoint Server. It does not mean every business using SharePoint through Microsoft 365 is running a vulnerable server.

What Is On-Premises SharePoint?

SharePoint is commonly used to store documents, organize internal information, and help employees collaborate.

Some businesses use SharePoint Online, which is hosted and maintained by Microsoft as part of Microsoft 365. Others operate SharePoint Server on equipment they own or manage. This is often called an on-premises or self-hosted installation.

A business may have an on-premises server because of an older technology decision, a specialized application, integration requirements, or a need to retain direct control over its systems.

The challenge is that self-hosted software requires someone to track security notices, test updates, install patches, review server exposure, and watch for suspicious activity. If that responsibility is unclear, important updates can be missed.

Why This Vulnerability Matters

The vulnerability involves a missing authentication check. In plain English, a vulnerable server may not correctly verify that someone is authorized before allowing certain actions.

The National Vulnerability Database records the vulnerability as affecting SharePoint Server and notes the federal guidance to apply vendor-recommended updates and mitigations.

For a small business, a compromised collaboration server could put several parts of the operation at risk:

  • Internal documents and business records
  • Employee or customer information stored in SharePoint
  • Accounts connected to the server
  • Other systems reachable from the affected environment
  • Business availability if the server must be taken offline
  • Customer trust if sensitive information is exposed

A business does not need to understand the technical details of the flaw. It does need to know whether it owns an affected system and who is responsible for securing it.

Questions to Ask Your IT Provider

Start with these practical questions:

  1. Do we operate an on-premises SharePoint Server? Do not assume that using Microsoft 365 automatically answers this question. Some organizations have a mixture of cloud and locally hosted systems.
  2. Which SharePoint version do we use? Your IT provider should identify the exact edition and confirm that it remains supported.
  3. Was the July 14 security update installed? Microsoft published version-specific updates, including KB5002891 for SharePoint Server 2016.
  4. Can the server be reached directly from the internet? An internet-facing business system usually needs faster patching and closer monitoring because it is exposed to a larger pool of potential attackers.
  5. Has the server been checked for suspicious activity? Installing an update closes the vulnerability, but it does not automatically prove that an already-exposed server was never accessed.
  6. Are temporary protections still being treated as temporary? Microsoft identified additional scanning controls as a mitigation, but a workaround should not replace the appropriate security update.

Make Server Ownership Clear

Security problems often persist because everyone assumes someone else is handling them.

Maintain a basic technology inventory showing which servers and important applications the business uses, whether they are cloud-hosted or self-hosted, who supports them, when they were last updated, and how they are monitored.

That simple record helps prevent an older server from quietly becoming an unmanaged business risk.

If your business uses SharePoint Server or is unsure what kind of SharePoint environment it has, Cybernetic Networks can help identify the system, review its update status, assess how it is exposed, and build a practical maintenance plan. A short review now can provide much more certainty than discovering an overlooked server during an incident.

Source Links

Quotes from our Customers