Hackers target Microsoft SharePoint RCE chain with PoC exploit
ID: 72ada3f8-ea2b-5653-a3bf-e76f3caf55ef
STIX ID: report--72ada3f8-ea2b-5653-a3bf-e76f3caf55ef
Feed Name: Bleeping Computer
Two chained Microsoft SharePoint vulnerabilities (CVE-2026-55040: JWT authentication bypass, and CVE-2026-63520: BCS RCE) have publicly available PoCs released in August and were quickly weaponized; Defused and other telemetry observed active probing and chaining of the flaws against honeypots. CISA has issued guidance to secure SharePoint servers, Shadowserver reports thousands of internet-exposed SharePoint instances, and prior exploited SharePoint flaws have been used by ransomware operators, highlighting elevated risk to unpatched on-premises SharePoint deployments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
