Microsoft SharePoint RCE Vulnerability: Hackers Exploit PoC for Remote Code Execution

www.news4hackers.com-microsoft-sharepoint-rce-vulnerability-hackers-exploit-poc-for-remote-code-execution-microsoft-sharepoint-rce-vulnerability-hackers-exploit-poc-for-remote-code-execution

Threat intelligence firm Defused reports active exploitation of two SharePoint vulnerabilities for remote code execution, with proof-of-concept exploits already in use.

Hackers are actively exploiting a two-vulnerability chain in Microsoft SharePoint to achieve remote code execution on unpatched systems, according to threat intelligence firm Defused.

Exploit Chain Overview

The attack vector combines an authentication bypass flaw with a remote code execution vulnerability, enabling adversaries to compromise SharePoint servers without requiring initial access credentials. Both flaws have been accompanied by proof-of-concept exploits.

CVE-2026-55040 and CVE-2026-63520 Details

CVE-2026-55040

The first vulnerability involves a flaw in the JSON Web Token (JWT) validation process that allows unauthorized users to perform actions as authenticated SharePoint site users or administrators.

CVE-2026-63520

The second vulnerability resides in the Business Connectivity Services (BCS) component and can be leveraged by attackers after exploiting the initial bypass to execute arbitrary code on the target system.

PoC Releases and Active Exploitation

Rapid7 researcher Stephen Fewer disclosed the PoC for CVE-2026-55040 on August 11, while VulnCheck researcher Jonathan Peterson released the PoC for CVE-2026-63520 on August 24. Within 24 hours of the first exploit’s release, Defused observed evidence of its use in active attacks.

Shadowserver’s Findings and CISA Directives

Shadowserver identified over 8,700 Microsoft SharePoint servers exposed to the public internet. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued directives on August 18 requiring federal agencies to address active exploitation of CVE-2026-55040.

Additional Vulnerabilities and Ransomware

CISA reiterated warnings on July 15 about three other SharePoint vulnerabilities (CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) being used to compromise on-premises SharePoint servers. On August 25, CISA confirmed that CVE-2026-45659 is now being used in ransomware campaigns.

Security Recommendations and Blue Report

CISA emphasized adherence to Microsoft’s security-hardening guidelines and advised against exposing SharePoint servers directly to the internet. The Blue Report 2026 highlights the need for continuous monitoring and mitigation of SharePoint-related risks.



About Author

en_USEnglish