# Attackers probe SharePoint authentication-bypass and RCE chain

_Published Wednesday, August 26, 2026 at 12:08 PM EDT · Security · Latest · Tier 1 — Major_

![Attackers probe SharePoint authentication-bypass and RCE chain — Primary](https://www.bleepstatic.com/content/hl-images/2026/08/26/Microsoft-SharePoint.jpg)

Threat actors are probing a chain of two Microsoft SharePoint vulnerabilities in Defused honeypots, BleepingComputer reported. CVE-2026-55040 is an authentication-bypass flaw in JWT token validation; attackers can chain it with CVE-2026-63520 in Business Connectivity Services for remote code execution on an unpatched server. Public proof-of-concept code for the two flaws was released August 11 and August 24. Defused said it saw the bypass followed by administrative enumeration and BCS probing, but no code execution in those observations.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-sharepoint-rce-chain-with-poc-exploit/)

---
Canonical: https://techandbusiness.org/newswire/gnqtdSAXZSYgEj8CZ-bjvx
Published: 2026-08-26T16:08:00.269Z
Story chronology: 2026-08-25T00:00:00.000Z
Retrieved: 2026-10-11T06:13:13.571Z
Publisher: Tech & Business (techandbusiness.org)
