Urgent.News

What's breaking now, across thousands of outlets.

Tech

SharePoint Authentication Bypass and RCE Chain Attack Observed: CVE-2026-55040 / CVE-2026-63520

1. Basic Information Article Title : Hackers target Microsoft SharePoint RCE chain with PoC exploit Publisher : BleepingComputer Publication Date : 2026-08-26 Original Source : BleepingComputer Related Sources : Rapid7 analysis of CVE-2026-55040 , VulnCheck analysis of CVE-2026-63520 , Microsoft CVE-2026-63520 advisory Related Malware, Threat Actors, CVEs, and Products : CVE-2026-55040,…

On August 26, 2026, security researchers BleepingComputer reported that hackers were exploiting vulnerabilities in Microsoft SharePoint to achieve remote code execution (RCE). The vulnerabilities, identified as CVE-2026-55040 and CVE-2026-63520, allow an unauthenticated attacker to bypass SharePoint's JSON Web Token (JWT) authentication.

Once the attacker gains access, they can enumerate various management functions and search for the Business Data Catalog (BCS) remote code execution (RCE) sink. However, the actual RCE execution has not been confirmed at the time of this report. The attack flow involves exploiting the JWT token validation flaw in CVE-2026-55040 to act as a SharePoint site user or administrator, followed by enumeration of management functions and probing for the CVE-2026-63520 sink in the Business Connectivity Services / Business Data Catalog.

While the honeypots observed the initial stages of the attack, they did not witness any actual code execution. To protect against these attacks, Microsoft has released security updates for both CVEs. It is recommended to apply these updates, stop direct internet exposure of SharePoint servers, and restrict management surfaces and BCS.

Additionally, blocking management operations after authentication bypass using applications, web application firewalls (WAFs), or network controls can further mitigate the risk. Observing abnormal JWTs, management endpoint enumeration, and Business Data Catalog requests in proxy, SWG, DNS, endpoint, and identity/IdP logs can indicate an ongoing attack.

In conclusion, the exploitation of CVE-2026-55040 and CVE-2026-63520 could lead to unauthorized access and arbitrary code execution on SharePoint servers, posing a significant security risk.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Hold up, there’s a new Twitter in the town

You read that right. There is a new social network called “Twitter.now” on the block, and it’s being operated by a startup called Operation Bluebird, whose founding team includes former Twitter…

  • Twitter.now launched by Operation Bluebird startup
  • Stephen Coates leads Operation Bluebird, former Twitter counsel
  • VERA AI system verifies posts, assigns trust scores

More from Thursday 27 August →