🔥 この記事の詳細
2026-08-11 更新
B
今週中

Microsoft SharePoint Serverのオンプレミス版において、認証なしでリモートコード実行(RCE)が可能な脆弱性の連鎖

脆弱性🌐 英語ソース📰 5記事🌐 3 countries
🇺🇸 US (3) · 🇮🇹 Italy · 🇹🇼 Taiwan
🖥️ 製品SharePoint
🔢 CVECVE-2026-55040CVE-2026-63520
📅 2026-08-11📰 hackernews
📌 一言でいうと
Microsoft SharePoint Serverのオンプレミス版において、認証なしでリモートコード実行(RCE)が可能な脆弱性の連鎖が発見されました。攻撃者はCVE-2026-55040を利用して任意のユーザー(管理者を含む)になりすまし、さらにCVE-2026-63520を組み合わせることでサーバー上でコードを実行できます。この脆弱性の発見にはAIエージェントが活用されており、SharePoint Server 2016, 2019, およびSubscription Editionが影響を受けます。
🔍該当判定
  • 自社で「SharePoint Server 2016」を運用している
  • 自社で「SharePoint Server 2019」を運用している
  • 自社で「SharePoint Server Subscription Edition」を運用している
上記いずれにも該当しない(SharePoint Onlineのみ利用、またはSharePointを未利用) → 静観でOK
該当時の対応
影響を受けるSharePoint Serverのバージョンを確認し、Microsoftが提供する最新のセキュリティ更新プログラムを速やかに適用してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Microsoft SharePoint Server 脆弱性 (CVE-2026-55040 / CVE-2026-63520) 対応について

お疲れさまです。SharePoint Serverにおける深刻な脆弱性の連鎖に関する情報共有です。

■ 概要
認証なしで任意のユーザーになりすます脆弱性 (CVE-2026-55040, CVSS 9.1) と、リモートコード実行 (RCE) を可能にする脆弱性 (CVE-2026-63520, CVSS 8.1) が組み合わされ、最終的に認証なしでのRCEが可能です。

■ 影響範囲
- SharePoint Server Subscription Edition
- SharePoint Server 2019
- SharePoint Server 2016
※SharePoint Onlineは影響を受けません。

■ 対応手順
1. 自社で運用しているSharePoint Serverのバージョンを確認してください。
2. Microsoft公式のセキュリティ更新プログラムを適用し、最新の状態にアップデートしてください。

■ 参考情報
- Microsoft Security Update Guide

対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] Microsoft SharePoint Server Vulnerabilities (CVE-2026-55040 / CVE-2026-63520)

Dear IT/Security Team,

We are sharing information regarding a critical exploit chain discovered in Microsoft SharePoint Server.

■ Overview
An exploit chain involving CVE-2026-55040 (CVSS 9.1), which allows unauthenticated identity assumption, and CVE-2026-63520 (CVSS 8.1), an unsafe .NET type instantiation, enables unauthenticated Remote Code Execution (RCE) on the server.

■ Affected Products
- SharePoint Server Subscription Edition
- SharePoint Server 2019
- SharePoint Server 2016
*SharePoint Online is NOT affected.

■ Mitigation Steps
1. Identify all on-premises SharePoint Server instances and their versions.
2. Apply the latest security updates provided by Microsoft immediately.

■ Reference
- Microsoft Security Update Guide

Priority: High
Deadline: Immediate