SharePoint RCE chain exploited in the wild after PoC release
Threat actors are actively exploiting a chain of two Microsoft SharePoint vulnerabilities, CVE-2026-55040 and CVE-2026-63520, to achieve remote code execution on unpatched servers. Public proof-of-concept exploits were released in August, and Defused observed the chain being probed in honeypots. CISA has ordered federal agencies to patch against these flaws, which affect internet-exposed SharePoint servers.
Related stories
CISA mandates three-day patch for exploited Zimbra vulnerability · Cybersecurity
Over 270 Zimbra servers compromised in ongoing RCE attacks · Cybersecurity
This summary is AI-generated and original to Mobble; the linked article is the authoritative source.
Original headline: “Hackers target Microsoft SharePoint RCE chain with PoC exploit.” Browse more stories.