Important correction: The previous article said exploitation had been observed. Microsoft's published assessment lists exploit maturity as Unproven for both CVEs, so that statement is withdrawn. CVE-2026-63520 is CVSS 8.1 High, not Medium.
Different flaws, different impact
CVE-2026-55040 is a security-feature bypass caused by weak authentication and is reachable by an unauthenticated network attacker. It is CVSS 9.1 Critical, with high confidentiality and integrity impact and no availability impact.
CVE-2026-63520 is remote code execution caused by improper input validation. It is unauthenticated and network reachable, but attack complexity is High. Its rating is CVSS 8.1 High.
Affected products
- ▸Microsoft SharePoint Enterprise Server 2016
- ▸Microsoft SharePoint Server 2019
- ▸Microsoft SharePoint Server Subscription Edition
Immediate action
- ✓Use each Microsoft CVE page to identify and install the update for the deployed product and build
- ✓Complete Microsoft-required post-installation steps such as the SharePoint Configuration Wizard
- ✓Review external exposure, administrator changes, web shells, unusual child processes, and IIS/SharePoint logs
- ✓Reduce unnecessary external reachability until updates are complete
