SharePoint RCE chain exploited in the wild after PoC release

Threat actors are actively exploiting a chain of two Microsoft SharePoint vulnerabilities, CVE-2026-55040 and CVE-2026-63520, to achieve remote code execution on unpatched servers. Public proof-of-concept exploits were released in August, and Defused observed the chain being probed in honeypots. CISA has ordered federal agencies to patch against these flaws, which affect internet-exposed SharePoint servers.
EXPANDED:
The exploit chain pairs an authentication bypass with a Business Connectivity Services flaw, allowing unprivileged attackers to escalate to remote code execution. Rapid7's PoC for the JWT bypass was weaponized within a day of publication, and Defused observed the full chain being probed by late August. Shadowserver tracks over 8,700 exposed SharePoint servers, though the number of patched or honeypot instances remains unclear.
CISA has added these flaws to its catalog of actively exploited vulnerabilities, ordering federal agencies to patch. Microsoft has not yet confirmed in-the-wild exploitation of the second flaw, but the agency has flagged 15 SharePoint