SharePoint-Summer-Header

IT Tips & Tricks

SharePoint Is Having a Rough Summer

Here’s What IT Needs to Know

Published 25 August 2026

If you’re responsible for an on-premises SharePoint® Server environment, summer 2026 has probably offered more “excitement” than anyone wanted.

There must be better ways to spend the lazy dog days of summer than reading security advisories over cold coffee, comparing SharePoint builds and wondering whether the words “remote code execution” are about to rearrange your week.

Are the words “remote code execution” about to rearrange your week?

Yet SharePoint security has demanded exactly that kind of attention.

Microsoft®, CISA and security researchers have documented a succession of serious SharePoint vulnerabilities during 2026. Some have been actively exploited. Others can become far more dangerous when combined.

For IT managers, MSPs and migration consultants, the practical message is simple: Patching matters, but understanding the environment around the patch matters too.

It’s Not Just Another Patch

Microsoft’s 9 June security update for SharePoint Server Subscription Edition addressed several security issues, including remote code execution (RCE) vulnerabilities.

Then July brought CVE-2026-55040. This vulnerability involves weak authentication in SharePoint Server. An attacker can exploit it over a network to bypass a security feature. Microsoft assigned it a Common Vulnerability Scoring System (CVSS) score of 9.1, placing it firmly in critical severity territory.

A critical CVSS score describes the severity of the vulnerability. It doesn’t mean every vulnerable server has been breached, but it does mean that “we’ll get to that next maintenance cycle” could be an uncomfortable attitude to explain later.

And then came August, and the picture became even more complicated.

Cybersecurity weaknesses have an unfortunate habit of making two plus two equal something much bigger than four.

Cybersecurity firm Rapid7 disclosed CVE-2026-63520, a SharePoint remote code execution vulnerability affecting supported versions of SharePoint Server. Successful exploitation can allow arbitrary code execution with the privileges of the Windows service account running the SharePoint site.

More importantly, Rapid7 demonstrated that CVE-2026-63520 can be chained with CVE-2026-55040 to create a critical unauthenticated remote code execution path.

That matters because security teams can’t always evaluate vulnerabilities as isolated entries in a spreadsheet. One weakness may open a door while another provides the route through the building. Cybersecurity weaknesses have an unfortunate habit of making two plus two equal something much bigger than four.

Some SharePoint Attacks Are Already Happening

The newly disclosed exploit chain also intersects with vulnerabilities already being used in real-world attacks.

In July, the Cybersecurity and Infrastructure Security Agency (CISA) warned that threat actors were actively exploiting several vulnerabilities affecting supported on-premises SharePoint Server versions. Reported activity included unauthorized access, remote code execution, theft of Internet Information Services (IIS) machine keys, persistence techniques and malware deployment.

On 18 August, CISA also added CVE-2026-55040 to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation.

CISA’s guidance goes well beyond “install the update.”

Organizations are advised to apply Microsoft’s latest patches, confirm that installation completed successfully and shorten patch cycles where possible. Administrators should also verify that appropriate security controls are enabled, review relevant telemetry and investigate signs that a vulnerable system may already have been compromised.

There’s a big difference between asking, “Are we patched now?” and asking, “What might have happened before we patched?”

The first is patch management. The second is security.

Why SharePoint Makes an Attractive Target

SharePoint is valuable because organizations have spent years making it valuable. A mature environment may contain contracts, financial information, engineering material, HR records, project histories, policies, procedures and intellectual property. It may also sit inside business processes that nobody thinks of as “SharePoint processes” anymore. Users simply know that this is where the work happens.

Avoid direct internet exposure for SharePoint Servers unless necessary.

Apps may depend on documents stored there. Teams may rely on long-established libraries. Spreadsheets may reference other files or data sources. Word documents can contain links to supporting files. Simple-looking workflows can hide a surprisingly elaborate web of dependencies.

That concentration of information and connectivity makes SharePoint useful to a business. It can also make a compromised server useful to an attacker.

Protecting SharePoint, therefore, means protecting more than just a web application. It means protecting part of the organization’s information architecture.

A Quick Note to MSPs (and IT Departments with Tech-Challenged Users)

What IT Teams Should Do Now

Don’t rely on a single SharePoint build number to confirm that the whole environment is fully patched. Check each server for missing updates, pending restarts or an upgrade-required status. Microsoft recommends keeping all servers in a SharePoint deployment at the same update and upgrade level.

A client may hear “the vulnerability is patched” as “the security incident is over.” But we both know those aren’t the same thing.

Security Can Expose a Second Problem: Data Dependencies

Security remediation often leads to infrastructure change.

An organization may decide to retire a legacy server, consolidate sites, reorganize libraries, restore content or accelerate a planned migration. A security event can turn a leisurely modernization project into a much more urgent one. That creates another risk.

Security-Patches

Security is more than constant patching.

Files don’t always live independently of one another.

Excel workbooks reference other workbooks. Documents contain hyperlinks to files elsewhere in the environment. OLE links, images and SharePoint content can depend on paths or locations that change when data moves. And on and on it goes.

A migration can therefore succeed at moving every file while damaging the relationships between those files. Everything arrived, but nothing’s connected the way it used to be.

“We Patched It” Shouldn’t End the Conversation

The recent SharePoint vulnerabilities are a reminder that familiar infrastructure can become easy to overlook. SharePoint may feel ordinary because people use it every day. The information stored inside it, however, is anything but ordinary.

For IT teams operating on-premises SharePoint, the immediate priorities are clear: Identify every exposed server, verify patch consistency across the deployment, confirm that AMSI and antimalware protections are functioning, inspect SharePoint and IIS telemetry for signs of exploitation, and rotate ASP.NET machine keys where compromise is suspected.

Then widen the lens.

Emergency-Response

Hopefully, you’ll never need it, but always have an emergency response plan in place.

Leave a Comment

Please note: All comments are moderated before they are published.





Recent Comments

  • No recent comments available.

Leave a Comment

Please note: All comments are moderated before they are published.