Microsoft SharePoint Server Multiple Vulnerabilities (Actively Exploited)
Severity Level: Critical
Date: 13/08/2026
Ref: CERT-NCSOC-0228
Components Affected
- Microsoft SharePoint Server Subscription Edition
- Microsoft SharePoint Server 2019 (end of support since 14 July 2026)
- Microsoft SharePoint Enterprise Server 2016 (end of support since 14 July 2026)
- Microsoft Project Server 2013 SP1 and Office Web Apps 2013 SP1
SharePoint Online (Microsoft 365) is not affected.
Overview
Multiple vulnerabilities have been identified in on-premises Microsoft SharePoint Server. A remote, unauthenticated attacker could chain two of these vulnerabilities to impersonate any user, including a site administrator, and execute arbitrary code on the affected server without requiring credentials or user interaction.
Proof-of-concept exploit code is publicly available and has already been observed in active attacks. A separate SharePoint remote code execution vulnerability has also been confirmed by CISA as being actively exploited in ransomware campaigns.
Description
A technical write-up and working proof-of-concept for CVE-2026-55040 were published on 11 August 2026. Within approximately twenty-four hours, the exploit was observed being used against internet-exposed SharePoint honeypots. The most significant vulnerabilities include:
- CVE-2026-55040 (CVSS 9.1) – Authentication bypass in the JWT validation pipeline, allowing an unauthenticated attacker to impersonate a chosen user and disclose files or modify data.
- CVE-2026-63520 (CVSS 8.1) – Unsafe .NET type instantiation in Business Connectivity Services, enabling execution of attacker-controlled code as the SharePoint site service account. When chained with CVE-2026-55040, this results in unauthenticated remote code execution.
- CVE-2026-45659 – Deserialization of untrusted data allowing a low-privileged attacker to execute arbitrary code. This vulnerability has been included in the CISA Known Exploited Vulnerabilities (KEV) Catalog and has been confirmed as exploited in ransomware campaigns.
- CVE-2026-65665, CVE-2026-64921, and CVE-2026-62827 – Additional critical SharePoint vulnerabilities addressed in the August 2026 security updates.
Internet-facing SharePoint deployments remain a significant target. Large numbers of exposed SharePoint servers have been identified, and multiple SharePoint vulnerabilities have historically been leveraged in ransomware operations.
Impact
- Remote Code Execution
- Authentication Bypass / User Impersonation
- Elevation of Privilege
- Information Disclosure and Data Manipulation
- Ransomware Deployment
Solution / Workarounds
Before installation of the software, please visit the vendor website for more details. Microsoft strongly recommends applying the latest security updates and cumulative updates.
Apply the following vendor updates:
- July 2026 update – Subscription Edition KB5002882 (16.0.19725.20434)
- SharePoint Server 2019 – KB5002883 (16.0.10417.20175)
- SharePoint Enterprise Server 2016 – KB5002891 (16.0.5561.1001)
- August 2026 cumulative update (released 11 August 2026) addressing CVE-2026-63520 and approximately twenty additional vulnerabilities
- May 2026 update addressing CVE-2026-45659
Recommended hardening and monitoring measures:
- Remove direct internet exposure where there is no documented business requirement
- Block external access to SharePoint Central Administration
- Place exposed SharePoint servers behind a Layer 7 reverse proxy or equivalent security control
- Enable AMSI integration for SharePoint web applications
- Verify endpoint protection is functioning correctly on all SharePoint servers
- Forward IIS access logs, Windows Security logs, and endpoint telemetry to the organisation’s monitoring platform
Organisations should verify patch status by build number rather than relying solely on patch management console reporting. For servers that were previously internet-exposed and unpatched, conduct a full compromise assessment, including web shell detection and machine key rotation where appropriate.
SharePoint Server 2016 and 2019 reached end of support on 14 July 2026 and no longer receive security updates. Migration should be treated as an urgent risk reduction measure.
Reference
- https://nvd.nist.gov/vuln/detail/CVE-2026-55040
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040
- https://learn.microsoft.com/en-us/officeupdates/sharepoint-updates
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Disclaimer
The information provided herein is based on public vendor and government sources available as of 13 August 2026 and is provided on an "as is" basis, without warranty of any kind.