KB5002906: what it fixes and who gets it

KB5002906 is a security update from Microsoft's August 2026 release for Microsoft SharePoint Enterprise Server 2016.

Microsoft data read
22CVEs fixed
2rated Critical
0already exploited
Norestart required

Should you install it?

Yes. It closes holes Microsoft rates Critical, the most serious rating it uses. Windows Update installs it automatically on supported home PCs.

If the installation fails or the PC misbehaves afterwards, note the exact error code first: the fix depends on it. Our update troubleshooting guides are linked on this page.

Security fixes in KB5002906

CVETypeCVSSSeverity
CVE-2026-62827Microsoft SharePoint Server Elevation of Privilege VulnerabilityElevation of Privilege8.8Critical
CVE-2026-64921Microsoft SharePoint Server Elevation of Privilege VulnerabilityElevation of Privilege8.8Critical
CVE-2026-63514Microsoft SharePoint Server Remote Code Execution VulnerabilityRemote Code Execution8.8Important
CVE-2026-64901Microsoft SharePoint Server Remote Code Execution VulnerabilityRemote Code Execution8.8Important
CVE-2026-65658Microsoft SharePoint Server Remote Code Execution VulnerabilityRemote Code Execution8.8Important
CVE-2026-65660Microsoft SharePoint Server Remote Code Execution VulnerabilityRemote Code Execution8.8Important
CVE-2026-65663Microsoft SharePoint Server Remote Code Execution VulnerabilityRemote Code Execution8.8Important
CVE-2026-66805Microsoft SharePoint Server Remote Code Execution VulnerabilityRemote Code Execution8.8Important
CVE-2026-66808Microsoft SharePoint Server Remote Code Execution VulnerabilityRemote Code Execution8.8Important
CVE-2026-70324Microsoft SharePoint Elevation of Privilege VulnerabilityElevation of Privilege8.8Important
CVE-2026-63520Microsoft SharePoint Server Remote Code Execution VulnerabilityRemote Code Execution8.1Important
CVE-2026-64900Microsoft SharePoint Server Spoofing VulnerabilitySpoofing7.3Important
CVE-2026-58639Microsoft SharePoint Server Spoofing VulnerabilitySpoofing6.5Important
CVE-2026-62837Microsoft SharePoint Server Information Disclosure VulnerabilityInformation Disclosure6.5Important
CVE-2026-62839Microsoft SharePoint Server Spoofing VulnerabilitySpoofing6.5Important
CVE-2026-63512Microsoft SharePoint Server Tampering VulnerabilityTampering6.5Important
CVE-2026-63516Microsoft SharePoint Server Spoofing VulnerabilitySpoofing6.5Important
CVE-2026-62917Microsoft SharePoint Server Spoofing VulnerabilitySpoofing4.6Important
CVE-2026-64897Microsoft SharePoint Server Spoofing VulnerabilitySpoofing4.6Important
CVE-2026-64902Microsoft SharePoint Server Spoofing VulnerabilitySpoofing4.6Important
CVE-2026-64916Microsoft SharePoint Server Spoofing VulnerabilitySpoofing4.6Important
CVE-2026-64922Microsoft SharePoint Server Spoofing VulnerabilitySpoofing4.6Important

Questions and experiences

Ask about this page: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

4,322 members already hereThey read, write, comment and vote. 0 verified · 31 joined this year

Cookies

We use essential cookies to run the platform. Analytics and marketing cookies are only turned on once you consent — you can change your choice at any time.