Microsoft’s August security updates completed remediation of a two-vulnerability unauthenticated remote code execution chain in on-premises SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. The chain combines CVE-2026-55040, an authentication bypass flaw patched in July with a CVSS score of 9.1, and CVE-2026-63520, the code-execution component patched in August. According to reporting cited by CERT Uganda, attackers can chain the flaws to forge a JSON Web Token, impersonate any SharePoint user or administrator, and gain full unauthenticated remote code execution.
Active exploitation of CVE-2026-55040 was confirmed in August, and CISA added the flaw to its Known Exploited Vulnerabilities catalog with an urgent remediation deadline. The SharePoint fixes landed amid Microsoft’s July 2026 security release, which addressed a record 570 vulnerabilities including two actively exploited zero-days. Organizations that applied only the July SharePoint update remain exposed to the full attack chain until the August cumulative update is installed.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
Defused Cyber confirmed active exploitation of CVE-2026-55040 on August 12 and August 13, 2026. The flaw affected on-premises SharePoint deployments and was later described as part of a full unauthenticated RCE chain.
A public proof-of-concept exploit for the SharePoint authentication bypass CVE-2026-55040 was released on August 11, 2026. The reference says active exploitation followed the PoC's publication, increasing the urgency for patching exposed on-premises SharePoint servers.
In August 2026 Patch Tuesday, Microsoft patched CVE-2026-63520, the code-execution component that completed remediation of the two-flaw SharePoint unauthenticated RCE chain. Rapid7 said the chain could let attackers forge a JSON Web Token, impersonate users or administrators, and execute server-side code on vulnerable on-premises SharePoint servers.
Microsoft patched CVE-2026-55040, the authentication bypass component of a SharePoint attack chain, in July 2026. Systems that applied only this July update remained exposed to the full unauthenticated RCE chain until the later patch was installed.
CISA added CVE-2026-55040 to its Known Exploited Vulnerabilities catalog and assigned an urgent patch deadline. The reference does not specify the date of CISA's action.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourcecybersecuritynews.com
Open sourcecert.ug
Open sourcebugflation.com
Open sourcegmcsirt.gm
Open sourcegov.br
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.