Microsoft SharePoint Vulnerabilities Targeted in Active Exploit Attempts
Threat intelligence firm Defused says attackers are targeting two Microsoft SharePoint vulnerabilities that could enable arbitrary code execution on unpatched servers.
The first vulnerability, tracked as CVE-2026-55040, is an authentication bypass flaw in SharePoint’s JSON Web Token (JWT) validation process. An unprivileged attacker could exploit the vulnerability to perform actions with the permissions of a SharePoint site user or administrator.
The second flaw, CVE-2026-63520, affects SharePoint’s Business Connectivity Services (BCS). An unauthenticated attacker could potentially chain it with CVE-2026-55040 to achieve remote code execution (RCE) on a vulnerable SharePoint Server.
Proof-of-concept (PoC) exploits for both vulnerabilities are publicly available. Rapid7 security researcher Stephen Fewer published a PoC for CVE-2026-55040 on August 11. VulnCheck vulnerability researcher Jonathan Peterson published a PoC for CVE-2026-63520 on August 24.
One day after the CVE-2026-55040 exploit code was published, Defused reported that Rapid7’s PoC had already been weaponized in attacks.
On August 25, the cybersecurity firm said attackers were chaining the SharePoint authentication bypass and remote code execution vulnerabilities against its honeypots.
“SharePoint CVE-2026-55040 + CVE-2026-63520 RCE chains are being investigated within honeypots,” Defused warned. “A JWT bypass (55040) was performed, followed by mass enumeration by administrators and investigation of the business data catalog sink behind CVE-2026-63520. No code execution has yet been observed.”
The Internet security nonprofit Shadowserver is tracking more than 8,700 Microsoft SharePoint servers exposed to the internet. However, it remains unclear how many of these systems are honeypots designed to detect exploitation attempts or how many are already protected against attacks targeting the vulnerabilities.

The US Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies and network defenders on August 18 to secure SharePoint servers against ongoing attacks exploiting CVE-2026-55040.
Although Microsoft has classified CVE-2026-63520 as a security vulnerability and it could attract interest from threat actors, the flaw has not yet been listed as exploited in the wild.
CISA also warned network defenders on July 15 to secure their systems against attacks actively exploiting three other vulnerabilities—CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164—to compromise internet-exposed, on-premises SharePoint Server instances.
Security officials are urging organizations to review Microsoft’s official SharePoint Server hardening guidance and avoid exposing SharePoint servers directly to the internet unless absolutely necessary.
On Tuesday, researchers confirmed that CVE-2026-45659, a SharePoint remote code execution vulnerability reportedly exploited since early July, is also being used in ransomware attacks.
Since November 2021, CISA has added 15 Microsoft SharePoint vulnerabilities to its warnings and tracking for actively exploited flaws. Eight of those vulnerabilities have also been used by ransomware operators.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




