EPC Group - Enterprise Microsoft AI, SharePoint, Power BI, and Azure Consulting
G2 High Performer Summer 2025, Momentum Leader Spring 2025, Leader Winter 2025, Leader Spring 2026
BlogContact
Ready to transform your Microsoft environment?Get started today
(888) 381-9725Get Free Consultation
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌

EPC Group

Enterprise Microsoft consulting with 29 years serving Fortune 500 companies.

(888) 381-9725
contact@epcgroup.net
4900 Woodway Drive, Suite 830
Houston, TX 77056

Follow Us

Solutions

  • M&A Practices

    • M&A Tenant Migration
    • Carve-Out Migration
    • Private Equity Practice
    • Engagement Operating Model
  • All Services
  • Microsoft 365 Consulting
  • AI Governance
  • Azure AI Consulting
  • Cloud Migration
  • Microsoft Copilot
  • Data Governance
  • Microsoft Fabric
  • Dynamics 365
  • Power BI Consulting
  • SharePoint Consulting
  • Microsoft Teams
  • vCIO / vCAIO Services
  • Large-Scale Migrations
  • SharePoint Development

Industries

  • All Industries
  • Healthcare IT
  • Financial Services
  • Government
  • Education
  • Teams vs Slack

Power BI

  • Case Studies
  • 24/7 Emergency Support
  • Dashboard Guide
  • Gateway Setup
  • Premium Features
  • Lookup Functions
  • Power Pivot vs BI
  • Treemaps Guide
  • Dataverse
  • Power BI Consulting

Company

  • About Us
  • Our History
  • Microsoft Gold Partner
  • Case Studies
  • Testimonials
  • Fixed-Fee Accelerators
  • Blog
  • Resources
  • All Guides & Articles
  • Video Library
  • Client Reviews
  • Engagement Operating Model
  • FAQ
  • Contact
  • Schedule a consultation

Microsoft Teams

  • Teams Questions
  • Teams Healthcare
  • Task Management
  • PSTN Calling
  • Enable Dial Pad

Azure & SharePoint

  • Azure Databricks
  • Azure DevOps
  • Azure Synapse
  • SharePoint MySites
  • SharePoint ECM
  • SharePoint vs M-Files

Comparisons

  • M365 vs Google
  • Databricks vs Dataproc
  • Dynamics vs SAP
  • Intune vs SCCM
  • Power BI vs MicroStrategy

Legal

  • Sitemap
  • Privacy Policy
  • Terms
  • Cookies

About EPC Group

EPC Group is a Microsoft consulting firm founded in 1997 (originally Enterprise Project Consulting, renamed EPC Group in 2005). 29 years of enterprise Microsoft consulting experience. EPC Group historically held the distinction of being the oldest continuous Microsoft Gold Partner in North America from 2016 until the program's retirement. Because Microsoft officially deprecated the Gold/Silver tiering framework, EPC Group transitioned to the modern Microsoft Solutions Partner ecosystem and currently holds the core Microsoft Solutions Partner designations.

Headquartered at 4900 Woodway Drive, Suite 830, Houston, TX 77056. Public clients include NASA, FBI, Federal Reserve, Pentagon, United Airlines, PepsiCo, Nike, and Northrop Grumman. 6,500+ SharePoint implementations, 1,500+ Power BI deployments, 500+ Microsoft Fabric implementations, 70+ Fortune 500 organizations served, 11,000+ enterprise engagements, 200+ Microsoft Power BI and Microsoft 365 consultants on staff.

About Errin O'Connor

Errin O'Connor is the Founder, CEO, and Chief AI Architect of EPC Group. Microsoft MVP multiple years, first awarded 2003. 4× Microsoft Press bestselling author of Windows SharePoint Services 3.0 Inside Out (MS Press 2007), Microsoft SharePoint Foundation 2010 Inside Out (MS Press 2011), SharePoint 2013 Field Guide (Sams/Pearson 2014), and Microsoft Power BI Dashboards Step by Step (MS Press 2018).

Original SharePoint Beta Team member (Project Tahoe). Original Power BI Beta Team member (Project Crescent). FedRAMP framework contributor. Worked with U.S. CIO Vivek Kundra on the Obama administration's 25-Point Plan to reform federal IT, and with NASA CIO Chris Kemp as Lead Architect on the NASA Nebula Cloud project. Speaker at Microsoft Ignite, SharePoint Conference, KMWorld, and DATAVERSITY.

© 2026 EPC Group. All rights reserved. Microsoft, SharePoint, Power BI, Azure, Microsoft 365, Microsoft Copilot, Microsoft Fabric, and Microsoft Dynamics 365 are trademarks of the Microsoft group of companies.

‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
SharePoint Server Critical Security Update (KB5002863) May 12, 2026: Patch Now - EPC Group enterprise consulting

SharePoint Server Critical Security Update (KB5002863) May 12, 2026: Patch Now

Microsoft released SharePoint Server security update KB5002863 on May 12, 2026 fixing 6 critical Remote Code Execution vulnerabilities including CVE-2026-40357. EPC Group urgent patching guide for SharePoint Server Subscription Edition, 2019, and 2016 environments.

HomeBlogMicrosoft News
Back to BlogMicrosoft News

SharePoint Server Critical Security Update (KB5002863) May 12, 2026: Patch Now

Microsoft released SharePoint Server security update KB5002863 on May 12, 2026 fixing 6 critical Remote Code Execution vulnerabilities including CVE-2026-40357. EPC Group urgent patching guide for SharePoint Server Subscription Edition, 2019, and 2016 environments.

EO
Errin O'Connor
CEO & Chief AI Architect
•
May 12, 2026
•
8 min read
SharePoint ServerSecurity UpdateCVE-2026Critical PatchMicrosoft NewsCybersecurityEmergency Patching
SharePoint Server Critical Security Update (KB5002863) May 12, 2026: Patch Now
8 min readPublished May 12, 2026

Key Takeaways

  • Microsoft released SharePoint Server security update KB5002863 on May 12, 2026 fixing 6 critical Remote Code Execution vulnerabilities including CVE-2026-40357. EPC Group urgent patching guide for SharePoint Server Subscription Edition, 2019, and 2016 environments.

SharePoint Server Critical Security Update — Patch Now

Microsoft released SharePoint Server security update KB5002863 on May 12, 2026, addressing 6 critical Remote Code Execution (RCE) vulnerabilities. This is an urgent patch for any organization still running SharePoint Server on-premises.

Quick Answer

Patch immediately. CVEs addressed: CVE-2026-40357, CVE-2026-33112, CVE-2026-33110, CVE-2026-40368, CVE-2026-35439, CVE-2026-40367. These are RCE vulnerabilities — unauthenticated attackers can execute arbitrary code on unpatched SharePoint Server. EPC Group's recommended action: patch within 72 hours of bulletin release for any internet-exposed SharePoint farm.

What's Affected

  • SharePoint Server Subscription Edition (KB5002863)
  • SharePoint Server 2019 (language pack update KB5002872)
  • SharePoint Server 2016 (separate KB)

If you're still running SharePoint on-premises (vs SharePoint Online), this affects you. SharePoint Online customers are protected by Microsoft's managed infrastructure.

Why This Patch is Urgent

SharePoint Server RCE vulnerabilities are exactly the attack pattern used in the 2023 0patch ToolShell incident and the 2025 Cuba ransomware campaigns targeting SharePoint farms. Once exploited:

  • Attacker gets code execution on SharePoint application server
  • Can pivot to SQL Server (SharePoint config + content DBs)
  • Can pivot to Active Directory via service account credentials
  • Can deploy ransomware across the SharePoint farm + connected systems

The combination of (a) network-reachable application server + (b) high-privilege service account + (c) connected SQL + AD = catastrophic blast radius.

EPC Group's Patching Runbook

Hour 0-4: Inventory + risk assessment

  1. Identify all SharePoint Server installations (Subscription Edition, 2019, 2016, 2013 EOL)
  2. Confirm internet exposure (extranet portals, public-facing farms, VPN-accessible)
  3. Identify SharePoint service account privileges (audit AD group memberships)

Hour 4-24: Test environment patching
4. Apply KB5002863 to test farm
5. Validate functionality (sites, custom solutions, search, workflows)
6. Document any breakage + workaround

Hour 24-72: Production patching
7. Backup full SharePoint farm (config + content DBs + customizations) before patching
8. Apply KB5002863 to production farms during maintenance window
9. Run SharePoint Health Analyzer + verify clean

Day 4+: Post-patch hardening
10. Audit SharePoint service account permissions (least privilege)
11. Restrict SharePoint extranet access via Conditional Access or VPN
12. Enable Defender for Identity monitoring on SharePoint service accounts
13. Verify SharePoint search indexing healthy (sometimes broken by security updates)

Strategic Recommendation: Migrate to SharePoint Online

If you're still on SharePoint on-premises in 2026, this CVE pattern will repeat. Microsoft is releasing security updates roughly monthly for SharePoint Server. Each patch is an operational event. Migration to SharePoint Online eliminates the patching burden entirely.

EPC Group SharePoint Online migration: 4-12 months depending on environment. See /blog/zero-loss-sharepoint-migration-runbook-2026 for the 32-step methodology. Cost typically pays back via operational savings within 18-24 months even before considering improved security posture.

Industry-Specific Concerns

Federal / DoD: SharePoint Server in GCC High needs patching with FedRAMP impact assessment.

Healthcare: SharePoint farms storing PHI need urgent patching. RCE exploitation = HIPAA breach event. 60-day breach notification clock starts on day of exploitation, not detection.

Financial Services: SharePoint farms in MNPI workflows + customer records need immediate patch. SEC Reg S-P + NYDFS 23 NYCRR 500 have prompt-patching requirements.

Manufacturing: SharePoint farms connected to OT networks (engineering drawings, IP, schematics) are high-value targets.

EPC Group Emergency Engagement

We're shipping emergency SharePoint Server patching engagements this week:

  • Same-week assessment + patching for SharePoint Subscription Edition / 2019 / 2016
  • Post-patch security hardening
  • Migration to SharePoint Online recommendation + roadmap

Typical scope: $40K-$120K depending on farm complexity (1-5 farm engagement).

Frequently Asked Questions

Q: Should we patch in maintenance window or emergency?
A: If internet-exposed: emergency (within 72 hours). If internal-only with strong network segmentation: scheduled maintenance window within 7 days.

Q: What if our SharePoint farm has heavy custom code?
A: Apply patch to test farm first. Validate custom solutions still work. Most full-trust + sandboxed solutions survive patches but always validate.

Q: What about SharePoint 2013 or older?
A: SharePoint 2013 and older are end-of-life. Microsoft is NOT releasing patches. Migration to SharePoint Online (or at minimum Subscription Edition) is the only option.

Q: How do we know if we're already compromised?
A: Microsoft Defender for Identity + Defender for Endpoint on SharePoint servers + audit log review. If you're unsure, engage incident response BEFORE patching (patching destroys forensic evidence).

Q: Why EPC Group?
A: 29 years SharePoint consulting since SharePoint 2003 Beta Team. Microsoft Solutions Partner with all six designations under the Microsoft AI Cloud Partner Program. Microsoft Press author (multiple SharePoint inside-out volumes). See /reviews and /industries/healthcare for regulated-industry experience.

Next Steps

  • Microsoft KB: https://support.microsoft.com/en-gb/topic/description-of-the-security-update-for-sharepoint-server-subscription-edition-may-12-2026-kb5002863-91158c5e-7155-47f8-86c2-9f8924cbfa12
  • Emergency SharePoint patching engagement: /contact
  • SharePoint Online migration runbook: /blog/zero-loss-sharepoint-migration-runbook-2026
  • SharePoint governance: /services/sharepoint-governance-consulting
  • Call (888) 381-9725 for same-week emergency engagement
Share this article:
EO

Errin O'Connor

CEO & Chief AI Architect

Microsoft Press bestselling author with 29 years of enterprise consulting experience.

View Full Profile

Related Articles

Microsoft News

Microsoft Agent 365 GA: Registry Sync with AWS Bedrock + Google Cloud (May 2026)

Microsoft Agent 365 became generally available May 1, 2026. New Registry Sync preview connects AWS Bedrock + Google Cloud agents for unified governance. Agent approval flow, network controls, $15/user/mo standalone or bundled in M365 E7. EPC Group governance breakdown.

Microsoft News

GPT 5.5 Instant in Microsoft 365 Copilot: Low Latency for Work Questions (May 2026)

Microsoft added GPT 5.5 Instant to Microsoft 365 Copilot in May 2026. Lower latency for common work questions, image-based inputs, and STEM tasks. What this changes for enterprise rollout + governance + EPC Group recommendations.

Microsoft News

Power BI May 2026 Feature Summary: New Power Query Get Data + Card States

Microsoft Power BI May 2026 update brings the redesigned Power Query Get Data experience (Preview), Card with States improvements, Copilot enhancements, and consistency across Fabric + Power BI Desktop + Excel. EPC Group breakdown + adoption guide.

Need Help with Microsoft News?

Our team of experts can help you implement enterprise-grade microsoft news solutions tailored to your organization's needs.

Microsoft News Consulting ServicesSchedule a Consultation