SharePoint security fixes released with August 2026 PU and offered through Microsoft Update

Important: If your current farm patch level is September 2025 CU, execute the following PowerShell script to correct the folder permissions on the relevant folders otherwise installing the SharePoint fixes will fail:
Fix-SeptemberCU-Permission-Problem.ps1

Alternatively you can also remove the NT Authority\system account from WSS_WPG and IIS_IUSRS local security groups of the SharePoint machines.

For more details check this article: Trending Issue: SharePoint fixes fail to install after installation of September 2025 CU

Below are the security fixes for the SharePoint OnPrem versions released this month.

SharePoint Server 2016:

  • KB 5002905 – SharePoint Server 2016 (language independent)
  • KB 5002906 – SharePoint Server 2016 (language dependent)

Microsoft Support recommends to install the complete August 2026 CU for SharePoint 2016 rather than individual security fixes.

SharePoint Server 2019:

  • KB 5002894 – SharePoint Server 2019 (language independent)
  • KB 5002896 – SharePoint Server 2019 (language dependent)

Microsoft Support recommends to install the complete August 2026 CU for SharePoint 2019 rather than individual security fixes.

SharePoint Server Subscription Edition:

  • KB 5002893 – SharePoint Server Subscription Edition

This security fix is identical with August 2026 CU for SharePoint Server Subscription Edition.

Office Online Server:

  • KB 5002895 – Office Online Server
Please ensure to have a look at the SharePoint Patching Best Practices before applying new fixes.

 


Security Vulnerabilities fixed in this PU

Vulnerability SP 2016 SP 2019 SP SE OOS Impact Max Severity
CVE-2026-57105 x x Spoofing Important
CVE-2026-58639 x x x Spoofing Important
CVE-2026-62827 x x x Elevation of Privilege Critical
CVE-2026-62829 x x Spoofing Important
CVE-2026-62837 x x x Information Disclosure Important
CVE-2026-62839 x x x Spoofing Important
CVE-2026-62917 x x x Spoofing Important
CVE-2026-63512 x x x Tampering Important
CVE-2026-63514 x x x Remote Code Execution Important
CVE-2026-63516 x x x Spoofing Important
CVE-2026-63520 x x x Remote Code Execution Important
CVE-2026-64897 x x x Spoofing Important
CVE-2026-64900 x x x Spoofing Important
CVE-2026-64901 x x x Remote Code Execution Important
CVE-2026-64902 x x x Spoofing Important
CVE-2026-64916 x x x Spoofing Important
CVE-2026-64921 x x x Elevation of Privilege Critical
CVE-2026-64922 x x x Spoofing Important
CVE-2026-65658 x x x Remote Code Execution Important
CVE-2026-65660 x x x Spoofing Important
CVE-2026-65663 x x x Remote Code Execution Important
CVE-2026-65665 x x Remote Code Execution Critical
CVE-2026-65807 x Remote Code Execution Important
CVE-2026-66805 x x x Remote Code Execution Important
CVE-2026-66808 x x x Remote Code Execution Important
CVE-2026-68793 x Remote Code Execution Important
CVE-2026-68794 x Remote Code Execution Critical
CVE-2026-68795 x Remote Code Execution Important
CVE-2026-68796 x Remote Code Execution Important
CVE-2026-68797 x Information Disclosure Important
CVE-2026-68799 x Information Disclosure Important
CVE-2026-68800 x Remote Code Execution Important
CVE-2026-68801 x Remote Code Execution Important
CVE-2026-68802 x Information Disclosure Important
CVE-2026-68803 x Remote Code Execution Important
CVE-2026-68804 x Remote Code Execution Critical
CVE-2026-68805 x Remote Code Execution Important
CVE-2026-68806 x Remote Code Execution Important
CVE-2026-68807 x Remote Code Execution Important
CVE-2026-68808 x Information Disclosure Important
CVE-2026-68810 x Remote Code Execution Important
CVE-2026-68811 x Remote Code Execution Important
CVE-2026-68812 x Remote Code Execution Important
CVE-2026-68814 x Remote Code Execution Important
CVE-2026-68815 x Remote Code Execution Important
CVE-2026-68816 x Remote Code Execution Critical
CVE-2026-68817 x Remote Code Execution Important
CVE-2026-70321 x Remote Code Execution Important
CVE-2026-70324 x x x Elevation of Privilege Important
CVE-2026-70326 x Elevation of Privilege Important
CVE-2026-70327 x Information Disclosure Important
CVE-2026-70328 x Information Disclosure Important
CVE-2026-70355 x x Elevation of Privilege Important

See the Security Update Guide below for more details about the relevant fixes:

16 Comments


  1. Hello Stefan,

    We have applied the August 2026 CU in SharePoint SE and SharePoint 2016 in test environment. Previously, we had issues with the workflow failing to start/failing to run and we were fixing them by adding the required assemblies on the web.config files. We have some questions:

    Do we need to remove the rewrite rule (which was the provided workaround on the workflow status URL) in the web.config files from the WFE server, or can it be retained?
    We noticed that below assembly has been gone in the web.config files after applying the August 2026 CU. Should we add it again?

    “”

    Thank you very much!

    Reply

    1. For the second question, here’s the assembly/authorizedType :

      authorizedType Assembly=”System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089″ Namespace=”System.CodeDom” TypeName=”*” Authorized=”True”

      Reply

      1. Afaik this is still required.

        Reply

    2. Hi Andre,

      You can remove rewrite rule if August CU is installed.

      Cheers,
      Stefan

      Reply

  2. After applying the update to our on-premises farm, the Document ID service has issues.

    This is empty
    $farm.GetGenericAllowedListValues(„AllowedDLCAssemblies“)
    across all environments.

    Reply

  3. All the workflows now have failed to start message since august 2026 CU on SharePoint SE

    Reply

    1. I forgot to mention I have this message when I try to publish them : Errors were found when compiling the workflow. The workflow files we saves but cannot be run. Unexpected error on server associating the workflow

      Reply

  4. The workflow still failed on start. It did not fix the default workflow issue.

    Reply

    1. Same problem here…. I applied the july update 2 weeks ago and did the fix from Stefan and it worked great. Since the august update, failed on start…

      Reply

    2. Looks like some could not wait until September CU. The Workflow Engines have been disabled with this Update in my Environments and i must enable them again.

      Reply

  5. I amd still getting “Unauthorized” from SPWFM workflows after installing the August 2026 SharePoint CU

    Reply

    1. Hi Ax,

      I would recommend to open a ticket with Microsoft support to get this analyzed in more detail.

      Cheers,
      Stefan

      Reply

  6. Hello! Thanks for your help. May I ask why this update exists? SharePoint 2016 reached its end of life on July, why did we get a new update? Can we expect more updates on the near future?

    Reply

    1. It contains fixes for security issues which were identified before end of life.

      No further updates are planned.

      Reply

  7. Search stopped working through out all our 2016 and 2019 farms. Any suggestions on this

    Reply

    1. Hi Siva,

      Please share more details.
      Is it search or crawl?
      What errors do you get in the UI and in ULS?

      Cheers,
      Stefan

      Reply

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.