Microsoft released SharePoint security updates KB5002863, KB5002868, and KB5002870 to fix multiple remote code execution vulnerabilities in SharePoint Server Subscription Edition, SharePoint Server 2016, and SharePoint Server 2019. The SharePoint 2016 and 2019 advisories cite Microsoft Word and SharePoint RCE issues including CVE-2026-40367, CVE-2026-40365, CVE-2026-40357, CVE-2026-33112, CVE-2026-33110, CVE-2026-35439, and CVE-2026-40368, while Microsoft’s download notices say exploitation could lead to arbitrary code execution when a maliciously modified file is opened. The patched builds are 16.0.19725.20280 for Subscription Edition, 16.0.5552.1002 for SharePoint 2016, and 16.0.10417.20128 for SharePoint 2019.
Microsoft said farms running SharePoint Workflow Manager must install KB5002799 before applying the cumulative updates, and deployments using Classic Workflow Manager must enable a debug flag to continue operating. The updates are available through Microsoft Update, the Microsoft Update Catalog, and the Microsoft Download Center, and they replace earlier SharePoint security updates including KB5002853, KB5002861, and KB5002854. In addition to the security fixes, Microsoft included nonsecurity corrections covering accessibility issues, unsafe user controls, page-loading errors, PowerShell database-exists errors, and ingestion cache throughput improvements.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft released SharePoint security updates KB5002863, KB5002868, and KB5002870 for SharePoint Server Subscription Edition, SharePoint Server 2016, and SharePoint Server 2019. The updates address multiple remote code execution vulnerabilities, including CVEs affecting SharePoint Server and Microsoft Word handling in SharePoint.
Microsoft published Security Update KB5002868 for SharePoint Server 2016. The notice says it addresses a vulnerability that could allow arbitrary code execution when a maliciously modified file is opened.
Microsoft published Security Update KB5002870 for SharePoint Server 2019 Core. The notice says it fixes a vulnerability that could allow arbitrary code execution when a maliciously modified file is opened.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
support.microsoft.com
Open sourcesupport.microsoft.com
Open sourcesupport.microsoft.com
Open sourcemicrosoft.com
Open sourcemicrosoft.com
Open sourcedocs.microsoft.com
Open sourcedocs.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.