MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-08-26 · via BleepingComputer

SharePoint RCE chain exploited in the wild after PoC release

Image via BleepingComputer
Image via BleepingComputer

Threat actors are actively exploiting a chain of two Microsoft SharePoint vulnerabilities, CVE-2026-55040 and CVE-2026-63520, to achieve remote code execution on unpatched servers. Public proof-of-concept exploits were released in August, and Defused observed the chain being probed in honeypots. CISA has ordered federal agencies to patch against these flaws, which affect internet-exposed SharePoint servers.

Expanded Detail

EXPANDED:

The exploit chain pairs an authentication bypass with a Business Connectivity Services flaw, allowing unprivileged attackers to escalate to remote code execution. Rapid7's PoC for the JWT bypass was weaponized within a day of publication, and Defused observed the full chain being probed by late August. Shadowserver tracks over 8,700 exposed SharePoint servers, though the number of patched or honeypot instances remains unclear.

CISA has added these flaws to its catalog of actively exploited vulnerabilities, ordering federal agencies to patch. Microsoft has not yet confirmed in-the-wild exploitation of the second flaw, but the agency has flagged 15 SharePoint

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Attackers exploit unpatched AhsayCBS bugs for webshells and cryptomining · Cybersecurity
CISA Adds Five Flaws to KEV Catalog After Flax Typhoon Attacks · Cybersecurity
AhsayCBS Bugs Abused to Install XMRig Miners and Web Shells · Cybersecurity
Exploit Released for AnyDesk Linux Flaw Allowing Root Access Before Authentication · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Hackers target Microsoft SharePoint RCE chain with PoC exploit.” Browse more stories.