CVE Tools
Back to feed
Exploited in the wild Microsoft SharePoint rce Microsoft auth-bypass

Hackers target Microsoft SharePoint RCE chain with PoC exploit

BleepingComputer·By Sergiu Gatlan··2 min read
CVE Tools coverage

Threat intelligence firm Defused reports that attackers are actively chaining Microsoft SharePoint vulnerabilities CVE-2026-55040 and CVE-2026-63520 to execute remote code on exposed infrastructure. The attack sequence begins with an unauthenticated JWT validation bypass that elevates privileges, followed by exploitation of a flaw in Business Connectivity Services to achieve full system compromise.

Public proof-of-concept exploits for both issues were released in August, and the authentication bypass has been observed in the wild since shortly after its disclosure. While Microsoft has identified the RCE component as a high-value target, CISA issued an emergency directive on August 18 requiring federal agencies to patch the server immediately due to active exploitation.