Hackers target Microsoft SharePoint RCE chain with PoC exploit

Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused.
The first (tracked as CVE-2026-55040) is an authentication bypass flaw in the JWT token validation pipeline that attackers without privileges can exploit to perform operations as a SharePoint site user or administrator.
The second (CVE-2026-63520) is a vulnerability in SharePoint's Business Connectivity Services (BCS) that unauthenticated attackers can chain after successfully exploiting CVE-2026-55040 for remote code execution (RCE) on a targeted SharePoint Server.
Both flaws have publicly available proof-of-concept (PoC) exploits, released by Rapid7 security researcher Stephen Fewer on August 11 (for CVE-2026-55040, representing the first part of the exploit chain) and by VulnCheck vulnerability researcher Jonathan Peterson on August 24 (for CVE-2026-63520).
One day after the CVE-2026-55040 PoC exploit was published online, Defused reported that Rapid7's exploit code had already been weaponized in attacks.
Roughly two weeks later, on August 25, the cybersecurity company said that threat actors are now chaining the SharePoint authentication bypass and RCE flaw in attacks targeting its honeypots.
"We're seeing the SharePoint CVE-2026-55040 + CVE-2026-63520 RCE chain probed in our honeypots," Defused warned on Tuesday. "The JWT bypass (55040) was exercised, followed by heavy admin enumeration and probing of the Business Data Catalog sink behind CVE-2026-63520. No code execution observed yet.
Internet security non-profit Shadowserver now tracks more than 8,700 Microsoft SharePoint servers exposed online. However, no details are available on how many are honeypots set up to catch exploitation attempts or how many have already been secured against attacks targeting these flaws.
Internet-exposed Microsoft SharePoint servers (Shadowserver)The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has already ordered federal agencies and network defenders on August 18 to secure their SharePoint servers against ongoing CVE-2026-55040 attacks.
While Microsoft has labeled the CVE-2026-63520 security flaw as an attractive target for threat actors, it has yet to tag it as exploited in the wild.
On July 15, CISA also warned network defenders to secure their servers against attackers who are actively exploiting three vulnerabilities (CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) to compromise Internet-exposed on-premises SharePoint Server instances.
The cybersecurity agency urged security teams to review Microsoft's official SharePoint Server security-hardening guidance and to avoid directly exposing SharePoint servers on the Internet unless necessary.
On Tuesday, it also confirmed that the CVE-2026-45659 SharePoint remote code execution vulnerability, flagged as exploited in the wild since early July, is now also being exploited in ransomware attacks.
Since November 2021, CISA has flagged 15 actively exploited Microsoft SharePoint flaws, eight of them also exploited by ransomware gangs.
References in this story
- NVD - CVE-2026-63520 nvd.nist.gov
- AI Threat Readiness Playbook for Cloud Security Teams | Wiz wiz.io Prepare for AI-driven threats. Discover best practices for exposure management, AI-powered code analysis, and real-time threat detection.
- Microsoft SharePoint JWT Token Authentication Bypass Technical Analysis (CVE-2026-55040) www.rapid7.com Technical Analysis of CVE-2026-55040, an authentication bypass affecting Microsoft SharePoint. This vulnerability is due to several issues in the JWT token validation pipeline.
- Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain | Blog | VulnCheck www.vulncheck.com Building a complete SharePoint exploit chain to get unauthenticated RCE via unsafe .NET type instantiation.
- Hackers leverage new Microsoft SharePoint exploit in attacks www.bleepingcomputer.com Hackers have already begun using a proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday.
- Defused (@DefusedCyber) on X x.com 🚨 We're seeing the SharePoint CVE-2026-55040 + CVE-2026-63520 RCE chain probed in our honeypots The JWT bypass (55040) was exercised, followed by heavy admin enumeration and probing of the Business Data Catalog sink…
- Time series · IoT device statistics · The Shadowserver Foundation dashboard.shadowserver.org
- CISA warns admins to patch actively exploited SharePoint flaws www.bleepingcomputer.com The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances.
- Security Update Guide - Microsoft Security Response Center msrc.microsoft.com
- CISA: Microsoft SharePoint flaw now exploited in ransomware attacks www.bleepingcomputer.com CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July.
- Known Exploited Vulnerabilities Catalog | CISA www.cisa.gov For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of…



