Two Microsoft SharePoint flaws could be chained for remote code execution
This digest was compiled by AI from multiple sources — links to the originals are below.

Attackers are chaining two Microsoft SharePoint vulnerabilities, CVE-2026-55040 and CVE-2026-63520, to execute arbitrary code on unpatched servers, according to threat intelligence firm Defused. The company observed the exploit chain being probed in its honeypots on August 25, following the release of proof-of-concept code by Rapid7 and VulnCheck researchers. CISA has ordered federal agencies to secure their SharePoint servers against ongoing attacks.
Key Facts
- CVE-2026-55040 is an authentication bypass flaw in SharePoint's JWT token validation pipeline that allows unprivileged attackers to operate as a site user or administrator.
- CVE-2026-63520 is a vulnerability in SharePoint Business Connectivity Services that enables remote code execution when chained after exploiting CVE-2026-55040.
- Rapid7 researcher Stephen Fewer published a proof-of-concept exploit for CVE-2026-55040 on August 11, and VulnCheck researcher Jonathan Peterson released a PoC for CVE-2026-63520 on August 24.
- Shadowserver tracks more than 8,700 internet-exposed Microsoft SharePoint servers, though the number of honeypots or already secured systems is unknown.
- CISA ordered federal agencies on August 18 to secure SharePoint servers against ongoing CVE-2026-55040 attacks.
Exploit Chain Details
The first vulnerability, CVE-2026-55040, is an authentication bypass in the JWT token validation pipeline that lets attackers without privileges perform operations as a SharePoint site user or administrator. The second flaw, CVE-2026-63520, resides in SharePoint's Business Connectivity Services and allows unauthenticated attackers to achieve remote code execution after successfully exploiting the first vulnerability. Proof-of-concept exploits for both flaws are publicly available, released by Rapid7's Stephen Fewer on August 11 and VulnCheck's Jonathan Peterson on August 24. Microsoft has labeled CVE-2026-63520 as an attractive target for threat actors but has not yet tagged it as exploited in the wild.
Observed Attack Activity
One day after the CVE-2026-55040 PoC was published, Defused reported that Rapid7's exploit code had already been weaponized in attacks. On August 25, Defused said threat actors are now chaining the SharePoint authentication bypass and RCE flaw in attacks targeting its honeypots. Defused warned that the JWT bypass was exercised, followed by heavy admin enumeration and probing of the Business Data Catalog sink behind CVE-2026-63520, though no code execution was observed yet. Shadowserver now tracks more than 8,700 Microsoft SharePoint servers exposed online, with no details on how many are honeypots or already secured.
Government Response
CISA ordered federal agencies and network defenders on August 18 to secure their SharePoint servers against ongoing CVE-2026-55040 attacks. On July 15, CISA also warned defenders to secure servers against attackers actively exploiting three other vulnerabilities—CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164—to compromise internet-exposed on-premises SharePoint Server instances. The agency urged security teams to review Microsoft's official SharePoint Server security-hardening guidance and avoid directly exposing SharePoint servers on the internet unless necessary.
1 source
Two Microsoft SharePoint flaws could be chained for remote code execution






