Top Advisory

Microsoft SharePoint Server Multiple Vulnerabilities (Actively Exploited)

Severity Level: Critical

Date: 13/08/2026

Ref: CERT-NCSOC-0228

Components Affected

SharePoint Online (Microsoft 365) is not affected.

Overview

Multiple vulnerabilities have been identified in on-premises Microsoft SharePoint Server. A remote, unauthenticated attacker could chain two of these vulnerabilities to impersonate any user, including a site administrator, and execute arbitrary code on the affected server without requiring credentials or user interaction.

Proof-of-concept exploit code is publicly available and has already been observed in active attacks. A separate SharePoint remote code execution vulnerability has also been confirmed by CISA as being actively exploited in ransomware campaigns.

Description

A technical write-up and working proof-of-concept for CVE-2026-55040 were published on 11 August 2026. Within approximately twenty-four hours, the exploit was observed being used against internet-exposed SharePoint honeypots. The most significant vulnerabilities include:

Internet-facing SharePoint deployments remain a significant target. Large numbers of exposed SharePoint servers have been identified, and multiple SharePoint vulnerabilities have historically been leveraged in ransomware operations.

Impact

Solution / Workarounds

Before installation of the software, please visit the vendor website for more details. Microsoft strongly recommends applying the latest security updates and cumulative updates.

Apply the following vendor updates:

Recommended hardening and monitoring measures:

Organisations should verify patch status by build number rather than relying solely on patch management console reporting. For servers that were previously internet-exposed and unpatched, conduct a full compromise assessment, including web shell detection and machine key rotation where appropriate.

SharePoint Server 2016 and 2019 reached end of support on 14 July 2026 and no longer receive security updates. Migration should be treated as an urgent risk reduction measure.

Reference

Disclaimer

The information provided herein is based on public vendor and government sources available as of 13 August 2026 and is provided on an "as is" basis, without warranty of any kind.

Footer Advisory