Skip to content

SharePoint Server RCE and Office Preview Pane Vulnerabilities Fixed in May Patch Tuesday — Enterprise Document Attack Surface Elevated

May's Patch Tuesday patches an authenticated RCE in SharePoint Server (CVE-2026-40365) and multiple Office vulnerabilities exploitable via the Windows Explorer and Outlook preview pane without opening files. Together they represent a significant enterprise document attack surface. Assess SharePoint exposure and validate Office update deployment this week.

Article security-assessment

Microsoft’s May 2026 Patch Tuesday includes fixes for an authenticated Remote Code Execution vulnerability in SharePoint Server (CVE-2026-40365) alongside several Office components exploitable via the preview pane — meaning malicious documents can trigger code execution without a user explicitly opening the file. These flaws collectively expand the document-as-delivery-vector attack surface that has dominated enterprise targeting patterns for the past five years.

SharePoint Server RCE — CVE-2026-40365

CVE-2026-40365 affects SharePoint Server in all supported on-premises configurations. Exploitation requires a valid domain account but no special SharePoint permissions — a standard employee account is sufficient. An authenticated attacker can send a crafted HTTP request to a SharePoint instance that triggers server-side code execution in the context of the SharePoint application pool service account.

The practical risk varies by deployment model:

DeploymentRisk Assessment
Intranet-only SharePointRequires pre-obtained enterprise credential; post-phishing attack path
SharePoint accessible from partner/extranet zonesHigh — partner accounts are routinely compromised
SharePoint accessible from internetCritical — any credential obtained via phishing provides exploitation
SharePoint Online (Microsoft 365)Not affected — this is an on-premises-only vulnerability

Patch: May 2026 Cumulative Update for SharePoint Server 2019 and SharePoint Server Subscription Edition.

Office Preview Pane Vulnerabilities

Several Office and Word/Excel RCEs addressed this month are exploitable via the preview pane in Windows Explorer or Outlook’s reading pane. This is a material distinction from vulnerabilities that require file opening: a user who navigates to a folder containing a malicious document, or selects an email attachment to preview, can be compromised without double-clicking to execute the file.

Preview-pane exploits are among the hardest to defend against in user-facing environments because they contradict user training — “don’t open suspicious files” — whilst previewing a file is not opening it in the traditional sense. Detection via endpoint telemetry is also more difficult because there is no explicit file execution event to alert on; the exploitation occurs within the shell or Outlook process.

Risk Assessment for Enterprise Environments

Security assessment teams reviewing May’s release should evaluate the following in their patch prioritisation:

  • SharePoint Server versions: Run Get-SPFarm | Select BuildVersion to confirm the current build and compare against the May 2026 Cumulative Update build number.
  • Externally accessible SharePoint: Any SharePoint farm with an endpoint reachable from outside the corporate network — including extranets, partner portals, and internet-published SharePoint — should be treated as having authenticated attacker access from the moment of patch publication.
  • Office patch compliance: Office client patching frequently lags Windows OS patching by one to two weeks in enterprise environments using SCCM or Intune. Use compliance reporting to identify endpoints where Office has not yet received May updates.
  • Prioritise SharePoint patching: Apply the May 2026 Cumulative Updates to all on-premises SharePoint Server farms within 48 hours. Confirm the update applied by checking the SharePoint Central Administration build version.
  • Assess SharePoint network exposure: Map which network zones can reach your SharePoint instances. Any zone accessible to accounts that can be phished — employees, contractors, partners — should be treated as having an authenticated attacker model.
  • Preview pane mitigation: Consider Group Policy settings that disable the Windows Explorer preview pane for managed endpoints that regularly handle externally sourced files. This is a mitigation, not a substitute for patching.
  • Validate Office update rollout: Pull compliance reports from Intune or SCCM to confirm Office client update deployment. Chase any straggler endpoints rather than assuming the update has applied.
  • Mark of the Web: Confirm that your email security gateway and endpoint controls correctly propagate MOTW (Mark of the Web) attributes to email-delivered attachments, enabling Protected View and additional Office security controls.

Share this article

Related Intelligence

🔬 Assessment

Pwn2Own Berlin 2026 Day 2: DEVCORE Chains Three Bugs for Exchange SYSTEM RCE — 15 Zero-Days and $385K Awarded

The second day of Pwn2Own Berlin saw DEVCORE's Orange Tsai chain three previously unknown vulnerabilities to achieve SYSTEM-level remote code execution on fully patched Microsoft Exchange Server, earning $200,000. Day 2 also featured Red Hat Enterprise Linux LPE, additional Windows 11 privilege escalation, and LM Studio AI exploitation across 15 unique zero-days.

#pwn2own +5
🔬 Assessment

March 2026 Brought 83 Patch Tuesday CVEs and Three CISA KEV Additions — How to Prioritise

March 2026's Patch Tuesday addressed 83 vulnerabilities including three critical Office RCEs, an Active Directory privilege escalation now in CISA's KEV catalogue, and a Kerberos security feature bypass. Add three separate CISA KEV additions throughout the month — F5 BIG-IP, Citrix NetScaler, and Active Directory — and security teams are managing a substantial patching backlog entering April. This analysis cuts through the volume to identify where to focus.

#vulnerability-management +5
🔬 Assessment

Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8): ShinyHunters Exploit Zero-Day to Breach University Student Records at Scale

A critical zero-day vulnerability in Oracle PeopleSoft Campus Solutions — CVE-2026-35273, CVSS 9.8 — has been exploited by the ShinyHunters threat group to breach student record systems at multiple universities across the US, UK, and Australia. The flaw allows unauthenticated attackers to bypass authentication in the PeopleSoft web application layer, granting direct access to student enrolment, financial aid, and academic records.

#oracle +8