By LinkedInEditors
Publication Date: 2026-08-26 21:00:00
Attackers are actively probing internet-exposed Microsoft SharePoint servers for a newly documented vulnerability chain capable of bypassing authentication and delivering remote code execution, intensifying pressure on organisations that have not yet installed Microsoft’s July and August 2026 security updates.
The emerging activity combines two vulnerabilities: CVE-2026-55040, a critical authentication bypass in SharePoint’s JSON Web Token validation process, and CVE-2026-63520, a high-severity flaw in SharePoint Business Connectivity Services that can be abused to execute arbitrary code.
Although each vulnerability has a different technical purpose, their combined effect is significantly more dangerous. The first can allow an unauthenticated attacker to impersonate a legitimate SharePoint user or administrator….
:max_bytes(150000):strip_icc()/GettyImages-2278970860-27cb02996df14cbc8907f3fcc14c9015.jpg?ssl=1)