FORSMILE
JA
セキュリティ2026/08/12

[URGENT] Microsoft SharePoint CVE-2026-55040, CVE-2026-63520: Update to the Latest Version — Unauthenticated RCE, Information Disclosure, Attacks Confirmed

Unauthenticated Remote Code Execution (RCE) and information disclosure vulnerabilities (CVE-2026-55040, CVE-2026-63520) have been discovered in Microsoft SharePoint Server, with attacks already confirmed. Apply the latest security updates immediately.

Back to Blog

Severe vulnerabilities (CVE-2026-55040, CVE-2026-63520) have been discovered in multiple versions of Microsoft SharePoint Server, allowing unauthenticated remote attackers to steal information and execute remote code (RCE). These vulnerabilities were patched as part of the monthly security updates released on August 11, 2026, and attacks have already been observed, necessitating urgent action.

Immediate Actions Required

  • Immediately apply the August 2026 security updates provided by Microsoft to all affected SharePoint Servers.
  • Apply any workarounds confirmed in official documentation (if available) to mitigate temporary risks.
  • Monitor system logs and network traffic for any signs of compromise.

Vulnerability Overview and Scope of Impact

The vulnerabilities reported affect Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. CVE-2026-55040 is rated with a CVSSv3.1 score of 9.1 (High), potentially allowing an unauthenticated remote attacker to obtain the identity of an arbitrary user. CVE-2026-63520, though rated with a CVSSv3.1 score of 8.1 (Medium), also poses a significant impact by enabling information disclosure and Remote Code Execution (RCE). If exploited by attackers, these vulnerabilities could lead to complete control over the SharePoint environment or the leakage of sensitive information.

⚠ CVE Score — 最高危険度 / CRITICAL
9.1CRITICALCVE-2026-55040

Specific Impacts and Attack Scenarios

If these vulnerabilities are exploited, an attacker could access the SharePoint Server without authentication, impersonate a user's identity, and potentially access sensitive information within the system. Particularly with CVE-2026-63520, attackers can execute arbitrary code remotely, leading to widespread and severe damage such as website defacement, data destruction or theft, and even the establishment of persistent access through backdoors. Given that attacks have actually been observed, immediate countermeasures are essential.

Response Procedures and Verification Methods

Applying the August 2026 monthly security updates provided by Microsoft is the most critical measure. After applying the updates, verify that your SharePoint Server is up to date. Download and install the relevant updates using Windows Update or the Microsoft Update Catalog. Once the update is complete, confirm that the system is functioning normally and that there are no abnormal accesses in the security logs.

📦
Amazon で関連書籍・ツールを検索
cybersecurity server security tools
Amazonで探す →(アソシエイトリンク)

Reference Sources and Official Patch Information

Related articles