logo

Hackers target Microsoft SharePoint RCE chain with PoC exploit

ID: 72ada3f8-ea2b-5653-a3bf-e76f3caf55ef

STIX ID: report--72ada3f8-ea2b-5653-a3bf-e76f3caf55ef

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: Sergiu Gatlan

...
...

Two chained Microsoft SharePoint vulnerabilities (CVE-2026-55040: JWT authentication bypass, and CVE-2026-63520: BCS RCE) have publicly available PoCs released in August and were quickly weaponized; Defused and other telemetry observed active probing and chaining of the flaws against honeypots. CISA has issued guidance to secure SharePoint servers, Shadowserver reports thousands of internet-exposed SharePoint instances, and prior exploited SharePoint flaws have been used by ransomware operators, highlighting elevated risk to unpatched on-premises SharePoint deployments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.