Cybercriminals are actively probing a chain of two Microsoft SharePoint vulnerabilities that, if fully exploited, would allow them to run arbitrary code on unpatched servers, according to threat intelligence firm Defused. The attacks target a pair of flaws that were disclosed earlier this month, and Defused reports seeing the combined exploit chain tested against its honeypot systems. No code execution has been observed in these probes yet, but the activity signals a heightened risk for organizations running exposed SharePoint instances.
The first vulnerability, tracked as CVE-2026-55040, is an authentication bypass flaw in the JWT token validation pipeline. It can be exploited by unprivileged attackers to perform actions as a SharePoint site user or administrator. The second issue, CVE-2026-63520, is a vulnerability in SharePoint's Business Connectivity Services (BCS) that allows unauthenticated attackers to achieve remote code execution after successfully chaining it with the first flaw. Both issues have publicly available proof-of-concept exploits.
The PoC for CVE-2026-55040 was released on August 11 by Rapid7 security researcher Stephen Fewer. According to Defused, that exploit code was already weaponized in attacks within one day of its publication. A second PoC for CVE-2026-63520 was released on August 24 by VulnCheck vulnerability researcher Jonathan Peterson. On August 25, Defused warned that attackers were combining the two exploits in attempts against its honeypots, with evidence of admin enumeration and probing of the Business Data Catalog sink tied to the second flaw.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has already taken action on the first vulnerability. On August 18, the agency ordered federal agencies and network defenders to secure their SharePoint servers against ongoing attacks exploiting CVE-2026-55040. Microsoft has described CVE-2026-63520 as an attractive target for threat actors but has not yet tagged it as exploited in the wild, according to the source article.
This new activity follows a broader pattern of attacks against Microsoft SharePoint. On July 15, CISA warned about three other actively exploited SharePoint vulnerabilities, tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, which were being used to compromise Internet-exposed on-premises servers. The agency has urged security teams to review Microsoft's official SharePoint Server hardening guidance and to avoid exposing SharePoint servers directly to the Internet unless necessary. On Tuesday, CISA also confirmed that CVE-2026-45659, a SharePoint RCE flaw flagged as exploited since early July, is now being used in ransomware attacks.
The non-profit security group Shadowserver currently tracks more than 8,700 Microsoft SharePoint servers exposed online, though it is unclear how many of those are honeypots or have already been patched. Since November 2021, CISA has flagged 15 actively exploited Microsoft SharePoint flaws, eight of which have also been leveraged by ransomware gangs. The ongoing targeting of SharePoint highlights the persistent risk facing organizations that run on-premises instances of the widely used collaboration platform.
More cybersecurity news from TechManNews.







