Attackers are chaining CVE-2026-55040 and CVE-2026-63520 to target unpatched Microsoft SharePoint servers for remote code execution, with Defused reporting active probing in honeypots. Both flaws have public proof-of-concept exploits, and CISA has warned defenders to secure SharePoint systems against ongoing attacks. #CVE-2026-55040 #CVE-2026-63520 #MicrosoftSharePoint #Defused #CISA
Keypoints
- Attackers are chaining two SharePoint flaws to gain remote code execution.
- CVE-2026-55040 is an authentication bypass in the JWT validation pipeline.
- CVE-2026-63520 affects Business Connectivity Services and follows CVE-2026-55040.
- Public PoC exploits were released by Stephen Fewer and Jonathan Peterson.
- CISA and Defused have reported active targeting of exposed SharePoint servers.