Hackers target Microsoft SharePoint RCE chain with PoC exploit

Microsoft SharePoint

Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused.

The first (tracked as CVE-2026-55040) is an authentication bypass flaw in the JWT token validation pipeline that attackers without privileges can exploit to perform operations as a SharePoint site user or administrator.

The second (CVE-2026-63520) is a vulnerability in SharePoint’s Business Connectivity Services (BCS) that unauthenticated attackers can chain after successfully exploiting CVE-2026-55040 for remote code execution (RCE) on a targeted SharePoint Server.

image

Both flaws have publicly available proof-of-concept (PoC) exploits, released by Rapid7 security researcher Stephen Fewer on August 11 (for CVE-2026-55040, representing the first part of the exploit chain) and by VulnCheck vulnerability researcher Jonathan Peterson on August 24 (for CVE-2026-63520).

One day after the CVE-2026-55040 PoC exploit was published online, Defused reported that Rapid7’s exploit code had already been weaponized in attacks.

Roughly two weeks later, on August 25, the cybersecurity company said that threat actors are now chaining the SharePoint authentication bypass and RCE flaw in attacks targeting its honeypots.

“We’re seeing the SharePoint CVE-2026-55040 + CVE-2026-63520 RCE chain probed in our honeypots,” Defused warned on Tuesday. “The JWT bypass (55040) was exercised, followed by heavy admin enumeration and probing of the Business Data Catalog sink behind CVE-2026-63520. No code execution observed yet.

Internet security non-profit Shadowserver now tracks more than 8,700 Microsoft SharePoint servers exposed online. However, no details are available on how many are honeypots set up to catch exploitation attempts or how many have already been secured against attacks targeting these flaws.

Internet-exposed Microsoft SharePoint servers
Internet-exposed Microsoft SharePoint servers (Shadowserver)

​The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has already ordered federal agencies and network defenders on August 18 to secure their SharePoint servers against ongoing CVE-2026-55040 attacks.

While Microsoft has labeled the CVE-2026-63520 security flaw as an attractive target for threat actors, it has yet to tag it as exploited in the wild.

On July 15, CISA also warned network defenders to secure their servers against attackers who are actively exploiting three vulnerabilities (CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) to compromise Internet-exposed on-premises SharePoint Server instances.

The cybersecurity agency urged security teams to review Microsoft’s official SharePoint Server security-hardening guidance and to avoid directly exposing SharePoint servers on the Internet unless necessary.

On Tuesday, it also confirmed that the CVE-2026-45659 SharePoint remote code execution vulnerability, flagged as exploited in the wild since early July, is now also being exploited in ransomware attacks.

Since November 2021, CISA has flagged 15 actively exploited Microsoft SharePoint flaws, eight of them also exploited by ransomware gangs.

article image

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report