CISA named Microsoft SharePoint on the Known Exploited Vulnerabilities catalog on 18 August 2026. CVE-2026-55040. The list is the news. The dates are the news. Want a how-to? You will not find it here.

Microsoft had already shipped the July updates. The federal due date on the card was 21 August. The book is public. The fixes exist. Defenders can close the door.

KEV catalog cards with CVE numbers and due dates, no faces
Catalog cards. CVE numbers and due dates. No faces. The Gold Standard. Download

CISA’s 18 August alert is four lines long and does not wander. “CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.” CVE-2026-33824, Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability. CVE-2026-55040, Microsoft SharePoint Weak Authentication Vulnerability. CVE-2026-59310, Broadcom VMware vCenter Path Traversal Vulnerability. CVE-2026-65400, Apple macOS Improper Authentication Vulnerability. Binding Operational Directive 26-04 is named on the same page. Federal civilian executive branch agencies have to treat KEV rows on the timetable the catalog prints. CISA encourages everyone else to use the same book. That is the whole alert. Names. Evidence of use. A directive. Not a recipe.

The KEV named SharePoint
The Standard illustrationDownload

The SharePoint card, as CISA printed it, is a weak-authentication vulnerability that “allows an unauthorized attacker to bypass a security feature over a network.” Date added: 18 August 2026. Due date: 21 August 2026. Forensic triage required under BOD 26-04: yes. Known ransomware campaign use: unknown. Required action, in CISA’s words: apply mitigations in accordance with vendor instructions, keep to BOD 26-04 and the forensics-triage note, or discontinue the product if mitigations are unavailable. Notes on the card point at Microsoft’s MSRC advisory for CVE-2026-55040 and at NVD. The ID. The product. The date. I'm not printing a packet.

NVD’s affected set is on-premises Microsoft SharePoint Server: Subscription Edition prior to build 16.0.19725.20434; SharePoint Server 2019 prior to 16.0.10417.20175; SharePoint Enterprise Server 2016 prior to 16.0.5561.1001. NVD published 14 July 2026, last modified 19 August. Censys, in an 25 August advisory, and Halo Security in its CVE note, both say SharePoint Online in Microsoft 365 is not affected and needs no action. That boundary is the vendors’ and the scanners’. Keep it. A cloud tenant is not an on-premises farm.

The July patches are the door that already exists. Independent write-ups matching those NVD builds — Censys, Halo Security, IONIX, Penligent, all citing Microsoft’s July 2026 security updates — list KB5002882 for Subscription Edition at build 16.0.19725.20434; KB5002883 for SharePoint Server 2019 at 16.0.10417.20175; KB5002891 for SharePoint Enterprise Server 2016 at 16.0.5561.1001. IONIX and Penligent also name the language-dependent companions in that July set, KB5002885 for 2019 and KB5002892 for 2016. I did not invent those KB numbers. I'm reprinting a clustered Microsoft-update list. Confirm on MSRC and on the installed farm build before you close the ticket. “The update is installed” is not a build number.

Rapid7’s Stephen Fewer is the named researcher on the public analyses. Rapid7 and Microsoft disclosed CVE-2026-55040 on 14 July 2026. On 11 August, Rapid7 published a technical analysis of that CVE. The same 11 August, Rapid7 and Microsoft disclosed a second SharePoint CVE, CVE-2026-63520, a remote-code-execution bug. Rapid7’s 24 August analysis of 63520 is dated because, Rapid7 wrote, a third party had already published details and the 30-day embargo was lifted early. VulnCheck published on 24 August that a chain of the two CVEs exists. Rapid7, the same day, wrote that combined with the authentication bypass, the resulting chain is unauthenticated remote code execution against a vulnerable SharePoint server. Researchers demonstrated that in a lab. I will not describe how. No chain recipe. No payload. No token walkthrough. The public fact is that a chain was published as existing, that a lab demonstration of unauthenticated code execution was claimed, and that Microsoft had already shipped patches for both CVEs — July for 55040, August for 63520.

Censys’s 25 August advisory lists the August builds that carry the 63520 fix: Subscription Edition 16.0.19725.20522 (KB5002893); SharePoint Server 2019 16.0.10417.20198 (KB5002894, KB5002896); SharePoint Enterprise Server 2016 16.0.5565.1001 (KB5002905, KB5002906). Rapid7 has said the July update for 55040 breaks the demonstrated chain on its own, because it is the first link; both patches are the complete door. Attribute that to Rapid7. Then go to Microsoft’s update guide. I'm not a substitute for either.

CVE-2026-63520 is not on the KEV catalog as of copy close. CVE-2026-55040 is. CISA added 55040 on evidence of exploitation. The companion stays a patched, disclosed RCE with public research behind it. The useful object remains the catalog row and the KB list.

The other 18 August cards belong on the same board. CVE-2026-33824: Microsoft IKE Service Extensions, double-free, added 18 August, due 21 August. CISA’s short title is the title. MSRC is the vendor note on the card. CVE-2026-59310: Broadcom VMware vCenter, path traversal, added 18 August, due 21 August. CISA says a threat actor with network access to vCenter could execute arbitrary code. Broadcom’s advisory is the vendor door. CVE-2026-65400: Apple macOS improper authentication, added 18 August, due 21 August. CISA’s title does not say Screen Sharing. Tanium, Security Affairs, and CISA-catalog mirrors locate the bug in macOS Screen Sharing and list Apple’s 6 August fixes as macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9. Attribute the Screen Sharing placement and those build numbers to those write-ups until you are on Apple’s own bulletin. The catalog named an Apple authentication bug. Apple shipped updates. That is the positive sentence.

A week earlier, 11 August, CISA had already added three other rows. CVE-2026-68820 is Microsoft Windows Ancillary Function Driver for WinSock, a use-after-free, elevation of privilege. CISA’s 11 August alert names it. Microsoft’s Security Update Guide released it 11 August as an Important elevation-of-privilege on that driver. Catalog mirrors put the KEV due date at 25 August. CVE-2026-20349 is Cisco Secure Firewall ASA and FTD. CVE-2026-72898 is Metabase SQL injection. Those two are the rest of that day’s clip. WinSock is the Windows card. The catalog named it. August Patch Tuesday is the vendor fix. Name the CVE. Name the driver. Name the date.

BOD 26-04 is why the due dates are short. The 18 August SharePoint, IKE, vCenter, and macOS cards all carried 21 August as the federal date. That date is behind us as of 2 September. The catalog does not delete a row because the due date has passed. It stays. Agencies that missed 21 August are still looking at a named, exploited bug with a vendor patch. CISA’s alert says KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. That is the bar. SharePoint met it. So did IKE, vCenter, macOS, and WinSock.

What I will not do is walk anyone through a bypass, a chain, or a lab payload. Rapid7 published analyses. VulnCheck published that a chain exists. CISA put 55040 in the book. Microsoft shipped KB5002882, KB5002883, and KB5002891 in July, and the August set Censys listed for 63520. NVD printed the builds. SharePoint Online, per Censys and Halo Security, is outside the affected set. The catalog named them. The patches shipped. Agencies have dates. Defenders can close the door. The book is public. The fixes exist. Name the IDs. Leave the how-to off.