SharePoint Vulnerabilities Chained Together for Remote Code Execution
Security researchers have discovered that hackers can exploit two critical vulnerabilities in Microsoft SharePoint to execute remote code on a vulnerable server.
The sequence involves chaining together a critical authentication bypass vulnerability, tracked as CVE-2026-55040, and an improper input validation flaw, tracked as CVE-2026-63520. A proof of concept was previously disclosed by researchers at Rapid7 on August 11th.
VulnCheck researchers confirmed that exploitation of CVE-2026-55040 was possible just days after the Rapid7 disclosure. While the authentication bypass vulnerability on its own is not very impactful, VulnCheck said it needs to be chained with CVE-2026-63520 to achieve maximum effect.
Rapid7's initial analysis and VulnCheck's subsequent findings have prompted a flurry of activity among security researchers and threat actors. Defuse researchers reported seeing probing activity against their honeypots involving the chained sequence on Tuesday, August 22nd.