Microsoft SharePoint Flaws Chain to Unauthenticated Remote Code Execution
ID: 432ba27f-d13b-59d7-ae82-12f7ab9bb805
STIX ID: report--432ba27f-d13b-59d7-ae82-12f7ab9bb805
Feed Name: Cyber Press
Microsoft has released patches for two critical SharePoint Server flaws (CVE-2026-55040 and CVE-2026-63520) that together can allow unauthenticated remote code execution: a JWT authentication bypass enabling impersonation and a Business Connectivity Services deserialization leading to code execution. Researchers observed active probes against the combined chain in honeypots, CISA added CVE-2026-55040 to its Known Exploited Vulnerabilities catalog, and administrators are urged to apply updates, reduce internet exposure, enable token signing protections, and investigate anomalous JWT and BCS activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
