Cybersecurity Threats Rampant as Hackers Target Microsoft SharePoint Servers
Threat actors are exploiting a pair of vulnerabilities in Microsoft’s SharePoint platform, allowing them to execute arbitrary code on unpatched servers. The chain of attacks involves a vulnerability in the JWT token validation pipeline, which can be exploited by attackers without privileges, and a subsequent remote code execution flaw in SharePoint’s Business Connectivity Services.
The first vulnerability, tracked as CVE-2026-55040, is an authentication bypass flaw that can be exploited to perform operations as a SharePoint site user or administrator. The second vulnerability, CVE-2026-63520, is a separate issue in SharePoint’s Business Connectivity Services that can be chained after successfully exploiting the first flaw for remote code execution on a targeted SharePoint Server.
Both flaws have publicly available proof-of-concept exploits, released by security researchers Stephen Fewer and Jonathan Peterson. According to threat intelligence company Defused, the CVE-2026-55040 PoC exploit was quickly weaponized in attacks just one day after it was published online. Now, Defused reports that threat actors are chaining the SharePoint authentication bypass and RCE flaw in attacks targeting its honeypots.
This is not an isolated incident; Microsoft SharePoint servers are a prime target for attackers. Internet security non-profit Shadowserver tracks over 8,700 exposed Microsoft SharePoint servers online, although it’s unclear how many of these are honeypots set up to catch exploitation attempts or how many have already been secured against attacks targeting these flaws.
The US Cybersecurity and Infrastructure Security Agency (CISA) has taken action to address this threat. On August 18, CISA ordered federal agencies and network defenders to secure their SharePoint servers against ongoing CVE-2026-55040 attacks. Microsoft has also flagged the CVE-2026-63520 security flaw as an attractive target for threat actors, although it has yet to confirm that it’s been exploited in the wild.
This vulnerability is just one of many actively exploited flaws in Microsoft SharePoint. Since November 2021, CISA has flagged 15 actively exploited Microsoft SharePoint vulnerabilities, with eight of them also being used by ransomware gangs. The Blue Report 2026 highlights the importance of robust security measures, noting that once attackers have valid credentials, only 37% of their actions are blocked.
To mitigate this threat, it’s essential to review and apply patches for both CVE-2026-55040 and CVE-2026-63520 as soon as possible. Additionally, avoiding direct exposure of SharePoint servers on the Internet unless necessary can help reduce the attack surface. With over 8,700 exposed Microsoft SharePoint servers online, it’s crucial that network defenders take proactive steps to secure their systems against these vulnerabilities.
Source: Bleeping Computer — 2026-08-26