CVE Tools

Hackers target Microsoft SharePoint RCE chain with PoC exploit

BleepingComputerBy Sergiu Gatlan

Reported exploitedMicrosoft SharePoint

Our summary

Threat intelligence firm Defused reports that attackers are actively chaining Microsoft SharePoint vulnerabilities CVE-2026-55040 and CVE-2026-63520 to execute remote code on exposed infrastructure. The attack sequence begins with an unauthenticated JWT validation bypass that elevates privileges, followed by exploitation of a flaw in Business Connectivity Services to achieve full system compromise.

Public proof-of-concept exploits for both issues were released in August, and the authentication bypass has been observed in the wild since shortly after its disclosure. While Microsoft has identified the RCE component as a high-value target, CISA issued an emergency directive on August 18 requiring federal agencies to patch the server immediately due to active exploitation.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store