Critical Vulnerabilities in Microsoft SharePoint Server
When chained together, CVE-2026-55040 and CVE-2026-63520 could lead to unauthenticated remote code execution against a vulnerable SharePoint server
Summary
When chained together, CVE-2026-55040 and CVE-2026-63520 could lead to unauthenticated remote code execution against a vulnerable SharePoint server
Affected platforms
The following platforms are known to be affected:
Threat details
Proof-of-concept exploit
A technical writeup and proof-of-concept details have been released for CVE-2026-55040. Security researchers are intending to release a technical writeup for CVE-2026-63520 next month which is likely to contain a proof-of-concept exploit.
The NHS England National CSOC assesses exploitation as highly likely following public disclosure of technical details.
SharePoint Server 2016 and 2019 are no longer supported
Microsoft's extended support for SharePoint Server 2016 and SharePoint Server 2019 has come to an end, therefore these products are now unsupported by Microsoft. Organisations are strongly encouraged to switch to a supported version.
Introduction
Microsoft has released security updates to address a critical vulnerabilities affecting Microsoft SharePoint Server.
- CVE-2026-55040 - 'Security Feature Bypass' vulnerability - CVSSv3 score: 9.1.
- CVE-2026-63520 - 'Remote Code Execution' vulnerability - CVSSv3 score: 8.1.
When chained together, CVE-2026-55040 and CVE-2026-63520 could lead to unauthenticated remote code execution against a vulnerable SharePoint server.
Remediation for CVE-2026-55040
NHS England issued High Severity Cyber Alert (HSA) CC-4818 on Wednesday 22 July 2026 to address CVE-2026-50522. Microsoft SharePoint Server instances vulnerable to CVE-2026-50522 are also vulnerable to CVE-2026-55040. Therefore, applying the security updates for CVE-2026-50522 will also remediate CVE-2026-55040.
Remediating CVE-2026-55040 removes a key component of the exploit chain, thus preventing unauthenticated remote code execution against vulnerable SharePoint servers. Additionally, affected organisations are encouraged to review Microsoft's security advisory for CVE-2026-55040 and security advisory for CVE-2026-63520 and apply the latest update as soon as possible.
Remediation advice
Affected organisations are encouraged to review Microsoft's security advisory for CVE-2026-55040 and security advisory for CVE-2026-63520 and apply the latest update as soon as possible.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 12 August 2026 12:26 pm