Microsoft's August 2026 Patch Tuesday closes the second half of a two-CVE unauthenticated remote code execution chain in SharePoint Server. The first half — CVE-2026-55040, a JWT authentication bypass — was disclosed and patched in July. Rapid7 disclosed the full chain on August 11 after coordinating with Microsoft: they chained CVE-2026-55040 with newly patched CVE-2026-63520, an unsafe .NET type instantiation flaw in SharePoint's Business Connectivity Services, to achieve full server takeover with no credentials required. No active exploitation has been confirmed yet, but Microsoft rates the new CVE as "exploitation more likely," and on-premises SharePoint Server administrators must apply the August update immediately.

What the Vulnerability Is

CVE-2026-63520 is an unsafe .NET type instantiation flaw in SharePoint's Business Connectivity Services (BCS) — a component that allows SharePoint to consume and display data from external business systems like SAP, SQL databases, and web services. When BCS processes specially crafted data, it instantiates a .NET type without properly validating what type is being created, allowing an attacker to supply a malicious type that executes arbitrary code in the context of the SharePoint service account.

On its own, CVE-2026-63520 requires an authenticated attacker. The critical risk emerges when it is chained with CVE-2026-55040 (the JWT token authentication bypass patched in July 2026). CVE-2026-55040 lets an unauthenticated attacker forge a valid SharePoint identity token if they know the target user's Active Directory SID or UPN. With a forged token in hand, the attacker is treated as an authenticated SharePoint user and can trigger CVE-2026-63520, resulting in remote code execution on the server with no valid account needed.

Rapid7 discovered this chain with significant assistance from an AI agent, logging 96 sessions, 256 prompts, and approximately 80,000 tool calls across 24 active days of agentic research — an early real-world demonstration of AI-accelerated vulnerability discovery in enterprise software.

Why It Matters

  • The fully unauthenticated RCE path is now public. When CVE-2026-55040 was disclosed in July, the companion RCE flaw was under coordinated embargo until Patch Tuesday. Both CVEs and the full exploit chain are now described in public research. Threat actors can begin building exploits.
  • Code runs as the SharePoint service account. The code execution lands with SharePoint service account privileges, which in most on-premises deployments are broad enough to reach databases, file shares, and integrated systems like Exchange and Active Directory.
  • SharePoint Server has a history of rapid exploitation. Prior SharePoint RCE CVEs (CVE-2026-45659, CVE-2026-50522, CVE-2026-58644) were exploited in ransomware campaigns within days or weeks of public disclosure.
  • On-premises deployments are the target. SharePoint Online and Microsoft 365 are not affected. Only self-hosted SharePoint Server (Subscription Edition, 2019, 2016) is at risk.
  • Patching CVE-2026-55040 alone breaks the chain. Organizations that applied the July 2026 cumulative updates have already severed the unauthenticated entry point. The August update closes CVE-2026-63520 as defense-in-depth and removes the authenticated exploitation path as well.

Am I Affected?

You are affected if you run any of the following on-premises products without applying the August 2026 cumulative updates: Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, SharePoint Server 2016, Microsoft Project Server, or Microsoft Office Web Apps Server.

You are not affected if you use SharePoint Online / Microsoft 365, or if you have already applied both the July 2026 updates (CVE-2026-55040) and August 2026 updates (CVE-2026-63520).

Check your SharePoint patch level in SharePoint Management Shell:

(Get-SPFarm).BuildVersion

Compare the output to Microsoft's official SharePoint build number list to confirm you are on the August 2026 build or later.

What to Do About It: Step-by-Step

1. Apply the August 2026 SharePoint Server cumulative update.

Download the August 2026 CU for your SharePoint Server version from Microsoft Update Catalog or Windows Update. After installation, run the SharePoint Products Configuration Wizard or the command-line equivalent:

psconfig.exe -cmd upgrade -inplace b2b -wait -force

2. Confirm CVE-2026-55040 (July patch) is also applied.

If you are not current on July 2026 updates, apply both July and August updates together. CVE-2026-55040 must be patched to sever the unauthenticated entry point. Check installed patches with:

Get-WmiObject -Class Win32_QuickFixEngineering | Where-Object {$_.HotFixID -like "KB*"}

3. Enable AMSI integration on SharePoint (defense in depth).

SharePoint's Antimalware Scan Interface (AMSI) integration can detect and block malicious payloads at the application layer. Enable it for all SharePoint web applications via SharePoint Central Administration or PowerShell.

4. Restrict or disable Business Connectivity Services if not in use.

If your organization does not use BCS external data connections, disable the feature at the web application level to remove the vulnerable code path entirely:

Disable-SPFeature -Identity "BDC3" -Url "http://yoursharepoint"

5. Restrict network access to SharePoint.

Ensure SharePoint servers are not directly reachable from the public internet. Place them behind a reverse proxy or WAF that enforces authentication before traffic reaches SharePoint. Exploiting CVE-2026-55040 requires knowing a valid user's SID or UPN; reducing Active Directory enumeration exposure raises the bar for that first step.

6. Monitor for unusual service account activity.

Because exploitation runs code as the SharePoint service account, watch for unexpected outbound connections, new process spawns from the IIS worker process (w3wp.exe), and unusual Business Connectivity Services operations in SharePoint ULS logs.

Quick-Win Checklist

  • Confirm SharePoint Server build version with (Get-SPFarm).BuildVersion
  • Apply July 2026 CU (patches CVE-2026-55040) if not already applied
  • Apply August 2026 CU (patches CVE-2026-63520) — this closes the full chain
  • Run psconfig.exe to complete the upgrade after CU installation
  • Enable AMSI integration on all SharePoint web applications
  • Verify SharePoint is not directly internet-facing (reverse proxy / WAF in place)
  • Disable BCS external data connections at the web app level if not in use
  • Monitor for anomalous activity from the SharePoint service account

Sources