Affected Systems
Microsoft SharePoint Server Subscription Edition, 2019, and 2016 (CVE-2026-55040, CVSS 9.1). Chained RCE flaw CVE-2026-63520 (CVSS 8.1) also affects Project Server 2013 SP1 and Office Web Apps 2013 SP1. SharePoint Online is not affected. SharePoint Server 2016 and 2019 reached end-of-support on July 14, 2026.
Exploitation Status
No known active exploitation as of July 14, 2026 per CISA. Proof-of-concept published by Rapid7 on August 11, 2026. CISA rated the attack automatable with total technical impact.
Business Impact
Unauthenticated attackers can assume any user identity (including admin) via JWT validation flaw if they know a user SID or UPN. When chained with CVE-2026-63520, attackers achieve remote code execution as the SharePoint service account. July patches break the exploit chain, but August patches addressing the RCE are not yet available. Organizations running end-of-life SharePoint 2016/2019 face uncertain patch availability for the RCE component.
Urgency
🔴 Immediate
Recommended Actions
- Immediately verify July 2026 updates are installed: Subscription Edition KB5002882 (build 16.0.19725.20434), SharePoint 2019 KB5002883 (build 16.0.10417.20175), SharePoint 2016 KB5002891 (build 16.0.5561.1001)
- Monitor Microsoft's SharePoint update history for August 2026 patches addressing CVE-2026-63520 and apply immediately upon release
- Hunt for indicators of compromise: review IIS machine key harvesting artifacts, unusual authentication patterns in SharePoint logs, and unexpected service account activity
- For SharePoint 2016 and 2019 (end-of-support July 14, 2026), plan migration to supported versions or implement compensating network segmentation and access controls
- Restrict network access to SharePoint servers to trusted IP ranges and enforce multi-factor authentication for all administrative accounts
