By Sergiu Gatlan
Publication Date: 2026-08-26 14:47:00
Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused.
The first (tracked as CVE-2026-55040) is an authentication bypass flaw in the JWT token validation pipeline that attackers without privileges can exploit to perform operations as a SharePoint site user or administrator.
The second (CVE-2026-63520) is a vulnerability in SharePoint’s Business Connectivity Services (BCS) that unauthenticated attackers can chain after successfully exploiting CVE-2026-55040 for remote code execution (RCE) on a targeted SharePoint Server.
Both flaws have publicly available proof-of-concept (PoC) exploits, released by Rapid7 security researcher Stephen Fewer on August 11 (for CVE-2026-55040, representing the first part of the exploit chain) and by VulnCheck vulnerability researcher Jonathan Peterson on August 24 (for CVE-2026-63520).
One…




