[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fZl5eujPMsC818DYT_pizV2EV9rgqzG2PaxLAdrWFxws":3},{"article":4,"iocs":55},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"24933471-fe2a-462f-9fca-9c796e68d8a0","Hackers target Microsoft SharePoint RCE chain with PoC exploit","hackers-target-microsoft-sharepoint-rce-chain-with-poc-exploit-8415d7","Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused. [...]","Attackers are actively exploiting a chain of two Microsoft SharePoint vulnerabilities (CVE-2026-55040 and CVE-2026-63520) to achieve remote code execution on unpatched servers. The first flaw bypasses authentication, allowing attackers to act as a user, and the second, in Business Connectivity Services, enables RCE when chained. Proof-of-concept exploits are publicly available, and threat actors have already weaponized the first vulnerability.","Hackers exploit chained Microsoft SharePoint vulnerabilities for RCE.","Hackers target Microsoft SharePoint RCE chain with PoC exploit By Sergiu Gatlan August 26, 2026 10:47 AM 0 Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused. The first (tracked as CVE-2026-55040) is an authentication bypass flaw in the JWT token validation pipeline that attackers without privileges can exploit to perform operations as a SharePoint site user or administrator. The second (CVE-2026-63520) is a vulnerability in SharePoint's Business Connectivity Services (BCS) that unauthenticated attackers can chain after successfully exploiting CVE-2026-55040 for remote code execution (RCE) on a targeted SharePoint Server. Both flaws have publicly available proof-of-concept (PoC) exploits, released by Rapid7 security researcher Stephen Fewer on August 11 (for CVE-2026-55040, representing the first part of the exploit chain) and by VulnCheck vulnerability researcher Jonathan Peterson on August 24 (for CVE-2026-63520). One day after the CVE-2026-55040 PoC exploit was published online, Defused reported that Rapid7's exploit code had already been weaponized in attacks. Roughly two weeks later, on August 25, the cybersecurity company said that threat actors are now chaining the SharePoint authentication bypass and RCE flaw in attacks targeting its honeypots. \"We're seeing the SharePoint CVE-2026-55040 + CVE-2026-63520 RCE chain probed in our honeypots,\" Defused warned on Tuesday. \"The JWT bypass (55040) was exercised, followed by heavy admin enumeration and probing of the Business Data Catalog sink behind CVE-2026-63520. No code execution observed yet. Internet security non-profit Shadowserver now tracks more than 8,700 Microsoft SharePoint servers exposed online. However, no details are available on how many are honeypots set up to catch exploitation attempts or how many have already been secured against attacks targeting these flaws. Internet-exposed Microsoft SharePoint servers (Shadowserver) ​The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has already ordered federal agencies and network defenders on August 18 to secure their SharePoint servers against ongoing CVE-2026-55040 attacks. While Microsoft has labeled the CVE-2026-63520 security flaw as an attractive target for threat actors, it has yet to tag it as exploited in the wild. On July 15, CISA also warned network defenders to secure their servers against attackers who are actively exploiting three vulnerabilities (CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) to compromise Internet-exposed on-premises SharePoint Server instances. The cybersecurity agency urged security teams to review Microsoft's official SharePoint Server security-hardening guidance and to avoid directly exposing SharePoint servers on the Internet unless necessary. On Tuesday, it also confirmed that the CVE-2026-45659 SharePoint remote code execution vulnerability, flagged as exploited in the wild since early July, is now also being exploited in ransomware attacks. Since November 2021, CISA has flagged 15 actively exploited Microsoft SharePoint flaws, eight of them also exploited by ransomware gangs. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: Hackers leverage new Microsoft SharePoint exploit in attacksCritical RCE flaw in Windows IKE Extension now actively exploitedCISA: Microsoft SharePoint flaw now exploited in ransomware attacksvBulletin fixes critical pre-auth RCE flaw with public exploitCISA warns admins to patch actively exploited SharePoint flaws","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhackers-target-microsoft-sharepoint-rce-chain-with-poc-exploit\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2026\u002F08\u002F26\u002FMicrosoft-SharePoint.jpg","2026-08-26T14:47:51+00:00","2026-08-26T16:00:25.307046+00:00",9,[18,21,24,26,28,30],{"name":19,"type":20},"Microsoft SharePoint","product",{"name":22,"type":23},"Microsoft","vendor",{"name":25,"type":20},"Business Connectivity Services",{"name":27,"type":23},"Defused",{"name":29,"type":23},"Rapid7",{"name":31,"type":23},"VulnCheck","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":32,"icon":34,"name":35,"slug":36},null,"Vulnerabilities","vulnerabilities",[38,43,48,50],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":44},{"id":45,"icon":34,"name":46,"slug":47},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":49},{"id":32,"icon":34,"name":35,"slug":36},{"category":51},{"id":52,"icon":34,"name":53,"slug":54},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[56,60,63,66,69],{"type":57,"value":58,"context":59},"cve","CVE-2026-55040","Authentication bypass flaw in JWT token validation",{"type":57,"value":61,"context":62},"CVE-2026-63520","Vulnerability in SharePoint's Business Connectivity Services (BCS) chained for RCE",{"type":57,"value":64,"context":65},"CVE-2026-32201","Previously warned about by CISA for SharePoint exploitation",{"type":57,"value":67,"context":68},"CVE-2026-45659","Previously warned about by CISA for SharePoint exploitation, now used in ransomware",{"type":57,"value":70,"context":65},"CVE-2026-56164"]