Microsoft SharePoint Servers Under Attack: Two Critical Flaws Exploited
Attackers are exploiting two Microsoft SharePoint vulnerabilities to execute arbitrary code on unpatched servers. The first vulnerability, tracked as CVE-2026-55040, is an authentication bypass flaw in the JWT token validation pipeline that can be exploited by attackers without privileges to perform operations as a SharePoint site user or administrator.
The second vulnerability, CVE-2026-63520, is in SharePoint's Business Connectivity Services (BCS) and can be chained with the first flaw for remote code execution on a targeted SharePoint Server. Both flaws have publicly available proof-of-concept exploits, released by security researchers Stephen Fewer and Jonathan Peterson.
Defused reported that Rapid7's exploit code had been weaponized in attacks just one day after its publication online. The company also warned that threat actors are chaining the SharePoint authentication bypass and RCE flaw in attacks targeting its honeypots.