Attackers exploiting RCE Chain with PoC to target SharePoint

27 Aug 2026

Security researchers from Defused, a threat intelligence company, have discovered two vulnerabilities in Microsoft SharePoint that attackers are exploiting to execute arbitrary code on unpatched servers.

 

Through this blog, we will understand what the vulnerabilities in Microsoft SharePoint are about, the threats they pose, and how organizations can defend against the threats posed by them.

About the vulnerabilities

Vendor + component affected 

CVEs/CVSS Score/Type 

Versions affected  

About 

 

Microsoft +  

SharePoint Server 2016, 2019, and Subscription Edition  

 

 

 

 

CVE-2026-55040/9.1(Critical)/ Authentication Bypass  

 

CVE-2026-63520/8.1(High)/ Remote Code Execution 

 

 

  • Microsoft SharePoint Enterprise Server 2016 – affected from 16.0.0 before 16.0.5561.1001 

 

  • Microsoft SharePoint Enterprise Server 2016 – affected from 16.0.0 before 16.0.5565.1001 

 

  • Microsoft SharePoint Server 2019 – affected from 16.0.0 before 16.0.10417.20175 

 

  • Microsoft SharePoint Server 2019 – affected from 16.0.0 before 16.0.10417.20198  

 

  • Microsoft SharePoint Server Subscription Edition – affected from 16.0.0 before 16.0.19725.20434 

 

  • Microsoft SharePoint Server Subscription Edition – affected from 16.0.0 before 16.0.19725.20522 

 

 

CVE-2026-55040 –  

 

This flaw lets unauthorized attackers carry out impersonation attacks by getting past authentication features over a network.  

 

CVE-2026-63520 –  

An unauthenticated attacker can exploit this flaw to execute arbitrary code remotely on a SharePoint Server. 

The threat posed by the vulnerabilities

Vulnerability  

What can an attacker do? 

 

CVE-2026-55040 

 

  • Bypass authentication on vulnerable SharePoint servers. 
  • Impersonate a SharePoint user/administrator.  
  • Access or modify SharePoint resources with the privileges of the account impersonated. 
  • Use the administrative privileges on SharePoint to further threat campaigns. 

 

 

CVE-2026-63520 

 

  • Execute arbitrary code on the affected SharePoint server. 
  • Access sensitive data on the SharePoint server. 
  • Modify SharePoint data and system configurations. 
  • Disrupt SharePoint services and the availability of SharePoint servers. 
  • Gain control of the affected SharePoint server. 

 

Microsoft has already released updates addressing the vulnerabilities. Organizations should immediately apply the latest applicable Security updates.

SharkStriker’s recommendation

  • Immediately patch affected SharePoint servers.
  • Prioritize Internet-facing SharePoint systems.
  • Verify SharePoint versions after patching.
  • Restrict unnecessary Internet exposure.

SharkStriker’s actions

  • Shared the advisory with the concerned team.
  • Recommended immediate patching and prioritization of Internet-facing systems.
  • Advised monitoring for exploitation attempts.

Get in Touch With us

We have explored what risk tolerance and risk appetite are and how important they are together in helping businesses align cybersecurity with their business goals. It can help CISOs, and C-suite make informed investment decisions for cybersecurity.

LEARN MORE