# Attackers probe SharePoint authentication-bypass and RCE chain

_Monday, August 24, 2026 at 8:00 PM EDT · Security · Latest · Tier 1 — Major_

![Attackers probe SharePoint authentication-bypass and RCE chain — Primary](https://www.bleepstatic.com/content/hl-images/2026/08/26/Microsoft-SharePoint.jpg)

Threat actors are probing a chain of two Microsoft SharePoint vulnerabilities in Defused honeypots, BleepingComputer reported. CVE-2026-55040 is an authentication-bypass flaw in JWT token validation; attackers can chain it with CVE-2026-63520 in Business Connectivity Services for remote code execution on an unpatched server. Public proof-of-concept code for the two flaws was released August 11 and August 24. Defused said it saw the bypass followed by administrative enumeration and BCS probing, but no code execution in those observations.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-sharepoint-rce-chain-with-poc-exploit/)

---
Canonical: https://techandbusiness.org/newswire/gnqtdSAXZSYgEj8CZ-bjvx
Retrieved: 2026-08-26T17:41:16.260Z
Publisher: Tech & Business (techandbusiness.org)
