Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft SharePoint CVE-2026-55040 + CVE-2026-63520 exploitation wave

Exploitation Wave
First reported
Last updated
Happening score
H score 42
1 unique sources, 1 articles

Summary

Hide ▲

Microsoft SharePoint servers exposed to the CVE-2026-55040 + CVE-2026-63520 chain are being probed for remote code execution, putting unpatched internet-facing systems at immediate risk. Public PoC releases and observed weaponization have turned the flaw pair into an active exploitation wave. Honeypot activity shows the JWT bypass being exercised, followed by admin enumeration and probing of the Business Connectivity Services path. No code execution has been confirmed yet, but the targeting is already broad across exposed SharePoint systems.

Related Happenings

FUXA path traversal flaw (CVE-2026-25895, actively scanned)

Vulnerability
H score49 First: 18.08.2026 20:44 Last: 18.08.2026 20:44 Sources 1

About this happening: Malicious scanning is targeting CVE-2026-25895 in FUXA <= 1.2.9, putting publicly exposed SCADA/HMI instances at risk of arbitrary file write and potential remote code...

Microsoft security patch release for CVE-2026-68820

Security Patch Release
H score28 First: 12.08.2026 00:28 Last: 12.08.2026 00:28 Sources 1

About this happening: Microsoft released August 2026 Patch Tuesday updates for Windows operating systems and supported software, fixing at least 398 vulnerabilities. The bundle includes...

SharePoint Server authentication-bypass authentication bypass flaw (multiple vulnerabilities)

Vulnerability
H score45 First: 11.08.2026 19:47 Last: 11.08.2026 19:47 Sources 1

How related: "The first (tracked as CVE-2026-55040) is an authentication bypass flaw in the JWT token validation pipeline that attackers without privileges can exploit to perform operations as a SharePoint site user or administrator. The second (CVE-2026-63520) is a vulnerability in SharePoint's Business Connectivity Services (BCS) that unauthenticated attackers can chain after successfully exploiting CVE-2026-55040 for remote code execution (RCE) on a targeted SharePoint Server."

About this happening: CVE-2026-55040 is a newly disclosed SharePoint Server authentication-bypass flaw that lets a remote unauthenticated attacker impersonate a chosen user, including an admini...

Latest development: 26.08.2026 17:47

Rapid7 security researcher Stephen Fewer releases a proof-of-concept exploit for CVE-2026-55040, the SharePoint authentication bypass in the JWT token validation pipeline that can let attackers perform operations as a site user or administrator.

CISA adds CVE-2026-12569 to KEV for PTC Windchill and FlexPLM

Public Sector Action
H score46 First: 26.06.2026 15:31 Last: 26.06.2026 15:31 Sources 1

About this happening: CISA added CVE-2026-12569 to the KEV catalog after finding active exploitation of PTC Windchill PDMlink and PTC FlexPLM, elevating the flaw to a federal remedi...

Microsoft SharePoint remote code execution (CVE-2026-45659)

Vulnerability
H score17 First: 26.05.2026 14:49 Last: 26.05.2026 14:49 Sources 1

About this happening: CVE-2026-45659 is a Microsoft SharePoint remote code execution vulnerability that affects unpatched SharePoint servers and can be triggered through deserializati...

Timeline

  1. 26.08.2026 17:47 1 articles · 2h ago

    Rapid7 publishes a PoC for the SharePoint JWT bypass in CVE-2026-55040

    Technical Analysis Update

    Rapid7 security researcher Stephen Fewer publishes a public proof-of-concept exploit for CVE-2026-55040, the authentication bypass in SharePoint's JWT token validation pipeline that can let an attacker act as a site user or administrator.

    Show sources
  2. 26.08.2026 17:47 1 articles · 2h ago

    CISA orders agencies to secure SharePoint servers against CVE-2026-55040

    Legal Policy Action Update

    CISA orders federal agencies and network defenders to secure Microsoft SharePoint servers against ongoing CVE-2026-55040 attacks and urges teams to review Microsoft's official SharePoint Server security-hardening guidance.

    Show sources
  3. 26.08.2026 17:47 1 articles · 2h ago

    VulnCheck publishes a PoC for the SharePoint BCS flaw in CVE-2026-63520

    Technical Analysis Update

    VulnCheck vulnerability researcher Jonathan Peterson publishes a public proof-of-concept exploit for CVE-2026-63520, the SharePoint Business Connectivity Services (BCS) flaw that can be chained after CVE-2026-55040 for remote code execution on a targeted SharePoint Server.

    Show sources
  4. 26.08.2026 17:47 1 articles · 2h ago

    Defused observes SharePoint exploit-chain probing in honeypots

    Exploitation Observed

    Defused says threat actors are chaining CVE-2026-55040 and CVE-2026-63520 in honeypot probes, with the JWT bypass exercised before heavy admin enumeration and probing of the Business Data Catalog sink behind CVE-2026-63520.

    Show sources
  5. 26.08.2026 17:47 2 articles · 2h ago

    Attackers target unpatched SharePoint servers with the CVE-2026-55040 plus CVE-2026-63520 chain

    Campaign Scope Update

    Threat intelligence company Defused says attackers are targeting unpatched Microsoft SharePoint servers with the CVE-2026-55040 + CVE-2026-63520 remote code execution chain, and no code execution has been observed yet.

    Show sources