Report Incident
× Home DPO CyberHub Rw-CSIRT Website About Rw-CSIRT Alerts Advisories About NCSA Documentation News & Events Topics Contact us Opportunities Privacy Policy

Alert: Active Exploitation of Microsoft SharePoint On-Premises Vulnerabilities

Microsoft has reported active exploitation of two vulnerabilities affecting on-premises Microsoft SharePoint Server. The first, CVE-2026-55040, is a weak authentication vulnerability that may allow an unauthorized attacker to bypass a SharePoint security feature over a network. The second, CVE-2026-63520, is an improper input validation vulnerability that may allow an unauthorized attacker to execute arbitrary code over a network.
 
Affected Systems:
  • SharePoint Subscription Edition: Versions prior to 16.0.19725.20522
  • SharePoint Server 2019: Versions prior to 16.0.10417.20198
  • SharePoint Server 2016 Enterprise: Versions prior to 16.0.5565.1001
 
Security Risks
 
Successful exploitation could allow attackers to bypass authentication or security controls and execute arbitrary code on affected SharePoint servers. Exploitation may result in unauthorised access, server compromise, data exposure, persistence, or further movement within the affected environment.
 
Recommended Actions
 
The National Cyber Security Authority (NCSA) recommends users and system administrators to take the following actions to mitigate the active exploitation of these vulnerabilities:
 
  • Update immediately to the latest supported version of Microsoft SharePoint Server to address the vulnerabilities and mitigate associated risks.
  • Follow the guidance provided by Microsoft and implement the recommended mitigations to minimize the risk
  • Ensure you have a recent backup that can be restored easily before applying updates or workarounds.
 
For further information and support, please contact the National Cyber Security Authority (NCSA) by email to rwcsirt@ncsa.gov.rw or call us on 9009.
 

References

02 September 2026

© 2026 National Cyber Security Authority