Hackers target Microsoft SharePoint RCE chain with PoC exploit

Hackers Exploit Chain of Microsoft SharePoint Vulnerabilities, Putting Thousands at Risk

Cybersecurity experts are sounding the alarm as threat actors have begun chaining two previously disclosed vulnerabilities in Microsoft SharePoint to gain unauthorized access and execute arbitrary code on unpatched servers. The combination of flaws allows attackers to bypass authentication and perform remote code execution (RCE) with relative ease.

The first vulnerability, CVE-2026-55040, is an authentication bypass flaw that enables attackers without privileges to exploit the JWT token validation pipeline in SharePoint. This vulnerability was publicly disclosed on August 11 by Rapid7 security researcher Stephen Fewer, who released a proof-of-concept (PoC) exploit for it. Just one day after its release, Defused reported that the exploit code had already been weaponized in attacks.

The second vulnerability, CVE-2026-63520, is a Business Connectivity Services (BCS) flaw that can be exploited by unauthenticated attackers who have successfully chained the first vulnerability. This RCE flaw allows attackers to execute arbitrary code on targeted SharePoint Servers, further increasing the risk of data breaches and system compromise.

Roughly two weeks after the CVE-2026-55040 PoC exploit was published online, Defused reported that threat actors are now chaining the SharePoint authentication bypass and RCE flaws in attacks targeting its honeypots. The cybersecurity company warned that “We’re seeing the SharePoint CVE-2026-55040 + CVE-2026-63520 RCE chain probed in our honeypots.”

This vulnerability chain is particularly concerning given the large number of exposed Microsoft SharePoint servers online. According to Shadowserver, an internet security non-profit, more than 8,700 Microsoft SharePoint servers are exposed online, although it’s unclear how many have been secured against these flaws.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has already ordered federal agencies and network defenders to secure their SharePoint servers against ongoing CVE-2026-55040 attacks. While Microsoft has labeled the CVE-2026-63520 security flaw as an attractive target for threat actors, it has yet to confirm whether it has been exploited in the wild.

This latest development underscores the importance of prioritizing security patching and following best practices for SharePoint Server deployment. As CISA’s warning emphasizes, network defenders should review Microsoft’s official SharePoint Server security-hardening guidance and avoid directly exposing SharePoint servers on the Internet unless necessary.

In light of this new threat, it is crucial that administrators take immediate action to secure their SharePoint environments. This includes applying available patches, reviewing system logs for suspicious activity, and implementing robust access controls to prevent unauthorized access. By staying vigilant and proactive in securing their systems, organizations can minimize the risk of falling victim to these attacks.


Source: Bleeping Computer — 2026-08-26