oxhak on Nostr: Attackers are probing a new exploit chain targeting unpatched Microsoft SharePoint ...
Attackers are probing a new exploit chain targeting unpatched Microsoft SharePoint servers. The chain combines CVE-2026-55040, an authentication-bypass flaw in JWT token validation, with CVE-2026-63520, a vulnerability in Business Connectivity Services that can enable remote code execution. The first flaw lets an unauthenticated attacker act as a SharePoint user or administrator before attempting the second stage.
Security firm Defused said on August 25 that it observed the chain being tested in honeypots. The activity included authentication-bypass attempts, administrator enumeration and probing of the Business Data Catalog, although no code execution had been seen in those observations. Proof-of-concept code for both vulnerabilities is publicly available. More than 8,700 SharePoint servers are exposed online, according to Shadowserver. CISA has urged defenders to apply Microsoft's security guidance and avoid exposing on-premises SharePoint to the internet unless necessary.
https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-sharepoint-rce-chain-with-poc-exploit/Published at
2026-08-26 15:07:03 UTCEvent JSON
{
"id": "735a4172930038ce0b40ba441eb4877f422817abb4acb40ce9d66e86ad7c0071",
"pubkey": "81b26cb98224311ea520a9042bf9c7cc78d2725d0a99f9797afd9a8a35970aaa",
"created_at": 1787756823,
"kind": 1,
"tags": [],
"content": "Attackers are probing a new exploit chain targeting unpatched Microsoft SharePoint servers. The chain combines CVE-2026-55040, an authentication-bypass flaw in JWT token validation, with CVE-2026-63520, a vulnerability in Business Connectivity Services that can enable remote code execution. The first flaw lets an unauthenticated attacker act as a SharePoint user or administrator before attempting the second stage.\n\nSecurity firm Defused said on August 25 that it observed the chain being tested in honeypots. The activity included authentication-bypass attempts, administrator enumeration and probing of the Business Data Catalog, although no code execution had been seen in those observations. Proof-of-concept code for both vulnerabilities is publicly available. More than 8,700 SharePoint servers are exposed online, according to Shadowserver. CISA has urged defenders to apply Microsoft's security guidance and avoid exposing on-premises SharePoint to the internet unless necessary.\n\nhttps://www.bleepingcomputer.com/news/security/hackers-target-microsoft-sharepoint-rce-chain-with-poc-exploit/",
"sig": "e16b7e56b2f49736c456f81fc9e5edf255f9359fd329b0893421c0777669005cc36b6a9a53ceed218ee020d12b6c42909783ec976799ae0bbf3d730c27558d27"
}