Microsoft SharePoint Flaws Let Unauthenticated Attackers Execute Remote Code
ID: a2eeeb14-bc25-56f0-86c0-6fac4d594c76
STIX ID: report--a2eeeb14-bc25-56f0-86c0-6fac4d594c76
Feed Name: GBHackers
**Critical SharePoint vulnerabilities enabling RCE:** Microsoft warned that two SharePoint Server flaws (CVE-2026-55040 — JWT authentication bypass, CVSS 9.1 — and CVE-2026-63520 — BCS deserialization leading to RCE, CVSS 8.1) can be chained to achieve unauthenticated remote code execution on on-premises servers; security firms observed active probes and attempted exploitation in honeypots, CISA added CVE-2026-55040 to its Known Exploited Vulnerabilities list, and administrators are urged to apply Microsoft patches, restrict public exposure, and investigate forged-token indicators and unusual Business Data Catalog activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
