Alert: Active Exploitation of Microsoft SharePoint On-Premises Vulnerabilities
Microsoft has reported active exploitation of two vulnerabilities affecting on-premises Microsoft SharePoint Server. The first, CVE-2026-55040, is a weak authentication vulnerability that may allow an unauthorized attacker to bypass a SharePoint security feature over a network. The second, CVE-2026-63520, is an improper input validation vulnerability that may allow an unauthorized attacker to execute arbitrary code over a network.
Affected Systems:
SharePoint Subscription Edition: Versions prior to 16.0.19725.20522
SharePoint Server 2019: Versions prior to 16.0.10417.20198
SharePoint Server 2016 Enterprise: Versions prior to 16.0.5565.1001
Security Risks
Successful exploitation could allow attackers to bypass authentication or security controls and execute arbitrary code on affected SharePoint servers. Exploitation may result in unauthorised access, server compromise, data exposure, persistence, or further movement within the affected environment.
Recommended Actions
The National Cyber Security Authority (NCSA) recommends users and system administrators to take the following actions to mitigate the active exploitation of these vulnerabilities:
Update immediately to the latest supported version of Microsoft SharePoint Server to address the vulnerabilities and mitigate associated risks.
Follow the guidance provided by Microsoft and implement the recommended mitigations to minimize the risk
Ensure you have a recent backup that can be restored easily before applying updates or workarounds.
For further information and support, please contact the National Cyber Security Authority (NCSA) by email to rwcsirt@ncsa.gov.rw or call us on 9009.