Skip to main content

Microsoft SharePoint Complete Unauthenticated RCE Chain Now Fully Patched Across Two Patch Tuesdays (CVE-2026-55040 / CVE-2026-63520)

Scope: Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016 (On-Premises Only)

Severity: Red

August's Patch Tuesday completed the remediation of the SharePoint unauthenticated RCE chain begun in July 2026, with CVE-2026-63520 closing the code execution component of a two-flaw attack chain whose authentication bypass half (CVE-2026-55040, CVSS 9.1) was patched last month. Rapid7's analysis confirms that an attacker who chains both flaws achieves full unauthenticated remote code execution on any on-premises SharePoint server by forging a JSON Web Token to impersonate any site user or administrator, then leveraging the August RCE component to execute server-side code. Active exploitation of CVE-2026-55040 was confirmed by Defused Cyber on August 12 and 13, and CISA added it to the KEV catalog with an urgent patch deadline. Organizations running on-premises SharePoint who applied July's update but have not yet applied August's cumulative update must do so immediately to fully close the chain.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.