Active Exploitation of Vulnerabilities in Microsoft SharePoint
28 August 2026
Attackers are exploiting multiple vulnerabilities in Microsoft SharePoint Server to bypass a security feature and run code over a network. Patch immediately.
Background
Microsoft is aware of the exploitation of multiple vulnerabilities (CVE-2026-55040, CVE-2026-63520) affecting Microsoft SharePoint. The vulnerabilities have Common Vulnerability Scoring System (CVSS v3.1) scores of: CVE-2026-55040 at 9.1 and CVE-2026-63520 at 8.1 out of 10.
Impact
Successful exploitation of these vulnerabilities could lead to the following:
CVE-2026-55040: Due to weak authentication in Microsoft Office SharePoint, an unauthorised attacker could bypass a security feature over a network.
CVE-2026-63520: Due to improper input validation in Microsoft Office SharePoint, an unauthorised attacker could execute code over a network.
Known Exploitation
These vulnerabilities are reportedly being actively exploited. A proof-of-concept exploit is publicly available.
Affected Products
These vulnerabilities affect the following products:
SharePoint Server Subscription Edition: versions before 16.0.19725.20522
SharePoint Server 2019: versions before 16.0.10417.20198
SharePoint Server 2016 Enterprise: versions before 16.0.5565.1001
Recommendations
Users and administrators of affected products are advised to update to the latest versions immediately.
References
https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-103/ (opens in new tab)
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040 (opens in new tab)
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63520 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-55040 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-63520 (opens in new tab)
