Microsoft SharePoint CVE-2026-55040 + CVE-2026-63520 exploitation wave
Exploitation Wave
Summary
Hide ▲
Show ▼
Microsoft SharePoint servers exposed to the CVE-2026-55040 + CVE-2026-63520 chain are being probed for remote code execution, putting unpatched internet-facing systems at immediate risk. Public PoC releases and observed weaponization have turned the flaw pair into an active exploitation wave. Honeypot activity shows the JWT bypass being exercised, followed by admin enumeration and probing of the Business Connectivity Services path. No code execution has been confirmed yet, but the targeting is already broad across exposed SharePoint systems.
Related Happenings
FUXA path traversal flaw (CVE-2026-25895, actively scanned)
Vulnerability
H score49
First: 18.08.2026 20:44
Last: 18.08.2026 20:44
Sources 1
About this happening:
Malicious scanning is targeting CVE-2026-25895 in FUXA <= 1.2.9, putting publicly exposed SCADA/HMI instances at risk of arbitrary file write and potential remote code...
FUXA path traversal flaw (CVE-2026-25895, actively scanned)
VulnerabilityAbout this happening: Malicious scanning is targeting CVE-2026-25895 in FUXA <= 1.2.9, putting publicly exposed SCADA/HMI instances at risk of arbitrary file write and potential remote code...
Microsoft security patch release for CVE-2026-68820
Security Patch Release
H score28
First: 12.08.2026 00:28
Last: 12.08.2026 00:28
Sources 1
About this happening:
Microsoft released August 2026 Patch Tuesday updates for Windows operating systems and supported software, fixing at least 398 vulnerabilities. The bundle includes...
Microsoft security patch release for CVE-2026-68820
Security Patch ReleaseAbout this happening: Microsoft released August 2026 Patch Tuesday updates for Windows operating systems and supported software, fixing at least 398 vulnerabilities. The bundle includes...
SharePoint Server authentication-bypass authentication bypass flaw (multiple vulnerabilities)
Vulnerability
H score45
First: 11.08.2026 19:47
Last: 11.08.2026 19:47
Sources 1
How related:
"The first (tracked as CVE-2026-55040) is an authentication bypass flaw in the JWT token validation pipeline that attackers without privileges can exploit to perform operations as a SharePoint site user or administrator.
The second (CVE-2026-63520) is a vulnerability in SharePoint's Business Connectivity Services (BCS) that unauthenticated attackers can chain after successfully exploiting CVE-2026-55040 for remote code execution (RCE) on a targeted SharePoint Server."
About this happening:
CVE-2026-55040 is a newly disclosed SharePoint Server authentication-bypass flaw that lets a remote unauthenticated attacker impersonate a chosen user, including an admini...
SharePoint Server authentication-bypass authentication bypass flaw (multiple vulnerabilities)
VulnerabilityHow related: "The first (tracked as CVE-2026-55040) is an authentication bypass flaw in the JWT token validation pipeline that attackers without privileges can exploit to perform operations as a SharePoint site user or administrator. The second (CVE-2026-63520) is a vulnerability in SharePoint's Business Connectivity Services (BCS) that unauthenticated attackers can chain after successfully exploiting CVE-2026-55040 for remote code execution (RCE) on a targeted SharePoint Server."
About this happening: CVE-2026-55040 is a newly disclosed SharePoint Server authentication-bypass flaw that lets a remote unauthenticated attacker impersonate a chosen user, including an admini...
Latest development: 26.08.2026 17:47
Rapid7 security researcher Stephen Fewer releases a proof-of-concept exploit for CVE-2026-55040, the SharePoint authentication bypass in the JWT token validation pipeline that can let attackers perform operations as a site user or administrator.
CISA adds CVE-2026-12569 to KEV for PTC Windchill and FlexPLM
Public Sector Action
H score46
First: 26.06.2026 15:31
Last: 26.06.2026 15:31
Sources 1
About this happening:
CISA added CVE-2026-12569 to the KEV catalog after finding active exploitation of PTC Windchill PDMlink and PTC FlexPLM, elevating the flaw to a federal remedi...
CISA adds CVE-2026-12569 to KEV for PTC Windchill and FlexPLM
Public Sector ActionAbout this happening: CISA added CVE-2026-12569 to the KEV catalog after finding active exploitation of PTC Windchill PDMlink and PTC FlexPLM, elevating the flaw to a federal remedi...
Microsoft SharePoint remote code execution (CVE-2026-45659)
Vulnerability
H score17
First: 26.05.2026 14:49
Last: 26.05.2026 14:49
Sources 1
About this happening:
CVE-2026-45659 is a Microsoft SharePoint remote code execution vulnerability that affects unpatched SharePoint servers and can be triggered through deserializati...
Microsoft SharePoint remote code execution (CVE-2026-45659)
VulnerabilityAbout this happening: CVE-2026-45659 is a Microsoft SharePoint remote code execution vulnerability that affects unpatched SharePoint servers and can be triggered through deserializati...
Timeline
-
26.08.2026 17:47 1 articles · 2h ago
Rapid7 publishes a PoC for the SharePoint JWT bypass in CVE-2026-55040
Technical Analysis UpdateRapid7 security researcher Stephen Fewer publishes a public proof-of-concept exploit for CVE-2026-55040, the authentication bypass in SharePoint's JWT token validation pipeline that can let an attacker act as a site user or administrator.
Show sources
- Hackers target Microsoft SharePoint RCE chain with PoC exploit — www.bleepingcomputer.com — 26.08.2026 17:47
-
26.08.2026 17:47 1 articles · 2h ago
CISA orders agencies to secure SharePoint servers against CVE-2026-55040
Legal Policy Action UpdateCISA orders federal agencies and network defenders to secure Microsoft SharePoint servers against ongoing CVE-2026-55040 attacks and urges teams to review Microsoft's official SharePoint Server security-hardening guidance.
Show sources
- Hackers target Microsoft SharePoint RCE chain with PoC exploit — www.bleepingcomputer.com — 26.08.2026 17:47
-
26.08.2026 17:47 1 articles · 2h ago
VulnCheck publishes a PoC for the SharePoint BCS flaw in CVE-2026-63520
Technical Analysis UpdateVulnCheck vulnerability researcher Jonathan Peterson publishes a public proof-of-concept exploit for CVE-2026-63520, the SharePoint Business Connectivity Services (BCS) flaw that can be chained after CVE-2026-55040 for remote code execution on a targeted SharePoint Server.
Show sources
- Hackers target Microsoft SharePoint RCE chain with PoC exploit — www.bleepingcomputer.com — 26.08.2026 17:47
-
26.08.2026 17:47 1 articles · 2h ago
Defused observes SharePoint exploit-chain probing in honeypots
Exploitation ObservedDefused says threat actors are chaining CVE-2026-55040 and CVE-2026-63520 in honeypot probes, with the JWT bypass exercised before heavy admin enumeration and probing of the Business Data Catalog sink behind CVE-2026-63520.
Show sources
- Hackers target Microsoft SharePoint RCE chain with PoC exploit — www.bleepingcomputer.com — 26.08.2026 17:47
-
26.08.2026 17:47 2 articles · 2h ago
Attackers target unpatched SharePoint servers with the CVE-2026-55040 plus CVE-2026-63520 chain
Campaign Scope UpdateThreat intelligence company Defused says attackers are targeting unpatched Microsoft SharePoint servers with the CVE-2026-55040 + CVE-2026-63520 remote code execution chain, and no code execution has been observed yet.
Show sources
- Hackers target Microsoft SharePoint RCE chain with PoC exploit — www.bleepingcomputer.com — 26.08.2026 17:47
- Hackers target Microsoft SharePoint RCE chain with PoC exploit — www.bleepingcomputer.com — 26.08.2026 17:47