Attempts Detected to Exploit Microsoft SharePoint by Chaining Two Vulnerabilities

Views: 90 views

468/69 Thursday, August 27, 2026

Threat intelligence company Defused disclosed that it detected attempts to attack Microsoft SharePoint by chaining two vulnerabilities: CVE-2026-55040, an authentication bypass vulnerability in JWT token validation, and CVE-2026-63520 in Business Connectivity Services (BCS). When used together, these vulnerabilities could allow code execution on unpatched SharePoint servers. Proof-of-concept (PoC) exploit code for both vulnerabilities has already been released publicly.

Reports indicate that CVE-2026-55040 was exploited after PoC code became available. Defused observed attackers attempting to use the flaw to bypass authentication, check for administrator accounts, and access the Business Data Catalog component associated with CVE-2026-63520 on a honeypot system. However, at the time of reporting, no successful code execution had been observed from the chained attack. Shadowserver also detected more than 8,700 Microsoft SharePoint servers exposed to the internet.

CISA recommends that organizations and administrators take steps to protect SharePoint Server from attacks, review Microsoft’s hardening guidance, and avoid exposing SharePoint Server directly to the internet unless necessary. Microsoft stated that CVE-2026-63520 is a vulnerability that is more likely to be targeted by attackers, but has not stated that it has been actively exploited.

Source: https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-sharepoint-rce-chain-with-poc-exploit/