Microsoft SharePoint servers are facing fresh attack activity after researchers disclosed proof-of-concept exploits for two vulnerabilities. The flaws can be chained together to bypass authentication and potentially achieve remote code execution. CVE-2026-55040 allows attackers to bypass SharePoint’s JWT authentication process. CVE-2026-63520 can then be used to execute arbitrary code on affected servers.
CVE-2026-55040 is a critical vulnerability with a CVSS score of 9.1 and can allow attackers without valid credentials to impersonate SharePoint users. In certain situations, attackers can impersonate privileged administrators and perform actions with their access. Rapid7 researcher Stephen Fewer published a proof-of-concept for the flaw on August 11. Microsoft had already released a security fix for the vulnerability.
The second flaw, CVE-2026-63520, affects SharePoint Business Connectivity Services and involves unsafe .NET type instantiation. The vulnerability can allow attackers to execute arbitrary code on vulnerable SharePoint servers. Rapid7 disclosed the issue on August 11 and warned that it becomes more dangerous when combined with the authentication bypass. Microsoft included a fix for the vulnerability in its August 2026 security updates.
Defused reported that attackers were testing the complete exploit chain against its honeypot systems. The observed activity included attempts to use the JWT authentication bypass followed by administrator enumeration. Attackers also probed the Business Data Catalog area associated with CVE-2026-63520. Defused said it had not observed successful code execution during this activity, but the behavior showed active testing of the attack path.
The latest activity follows earlier exploitation attempts targeting CVE-2026-55040 after its proof-of-concept became public. Security researchers observed attackers using the published exploit against vulnerable SharePoint systems. CISA also added CVE-2026-55040 to its Known Exploited Vulnerabilities catalog. The activity highlights how quickly publicly available exploit code can be adopted by attackers.
Organizations running on-premises SharePoint should treat these vulnerabilities as a serious security concern, especially when servers are exposed to the internet. Administrators should install Microsoft’s available security updates and review systems for suspicious authentication or administrator activity. Exposed SharePoint deployments should also be hardened wherever possible. While successful code execution has not been reported in the latest activity, attackers are actively testing the chain that could lead to it.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news