Skip to main content
Back to Newswire
Security

Attackers probe SharePoint authentication-bypass and RCE chain

Attackers probe SharePoint authentication-bypass and RCE chain Image: Primary
Threat actors are probing a chain of two Microsoft SharePoint vulnerabilities in Defused honeypots, BleepingComputer reported. CVE-2026-55040 is an authentication-bypass flaw in JWT token validation; attackers can chain it with CVE-2026-63520 in Business Connectivity Services for remote code execution on an unpatched server. Public proof-of-concept code for the two flaws was released August 11 and August 24. Defused said it saw the bypass followed by administrative enumeration and BCS probing, but no code execution in those observations.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire