Two SharePoint Flaws Give Hackers a Path to Remote Code Execution
Microsoft SharePoint vulnerabilities CVE-2026-55040 and CVE-2026-63520 are now drawing active attacker interest, with researchers spotting attempts to chain the flaws against exposed servers.
The two vulnerabilities can allow attackers to bypass authentication and potentially achieve remote code execution on unpatched SharePoint systems.
Attackers chain two SharePoint vulnerabilities
CVE-2026-55040 affects SharePoint’s JWT token validation pipeline and allows unauthenticated attackers to bypass authentication.
Successful exploitation can let an attacker perform operations as a SharePoint site user or administrator.
The second vulnerability, CVE-2026-63520, affects SharePoint Business Connectivity Services. Attackers can combine it with CVE-2026-55040 to potentially execute code remotely.
Public proof-of-concept exploits now exist for both vulnerabilities.
Rapid7 researcher Stephen Fewer released a CVE-2026-55040 PoC on August 11. Just one day later, Defused reported that attackers had already weaponized the exploit in real-world attacks.
VulnCheck researcher Jonathan Peterson then released a CVE-2026-63520 PoC on August 24.
Attackers are already probing the full exploit chain
On August 25, Defused detected attackers testing the complete CVE-2026-55040 and CVE-2026-63520 chain against its honeypots.
The attackers successfully triggered the JWT authentication bypass before carrying out extensive administrator enumeration and probing the vulnerable Business Data Catalog component.
At the time of Defused’s report, researchers had not observed successful remote code execution through the full chain.
CISA urges organizations to secure SharePoint servers
CISA ordered U.S. federal agencies and network defenders on August 18 to protect SharePoint servers from ongoing CVE-2026-55040 attacks.
Microsoft considers CVE-2026-63520 an attractive target for attackers, although the company has not yet classified the flaw as exploited in the wild.
CISA recommends following Microsoft’s SharePoint Server security-hardening guidance. Organizations should also avoid exposing on-premises SharePoint servers directly to the Internet unless they have a specific operational requirement.
In other security news, Microsoft recently fixed a major Entra ID security flaw.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages