Affected Systems

Microsoft SharePoint Server (on-premises). CVE-2026-55040: JWT authentication bypass. CVE-2026-63520: Business Connectivity Services RCE. Over 8,700 SharePoint servers exposed online. Specific vulnerable versions not disclosed in article.

Exploitation Status

Active exploitation confirmed. CVE-2026-55040 weaponized within one day of PoC release (August 11). Chained exploitation with CVE-2026-63520 observed in honeypots as of August 25. PoC exploits publicly available for both vulnerabilities (Rapid7 and VulnCheck). CISA ordered federal agencies to patch on August 18.

Business Impact

Unauthenticated attackers can chain these flaws to achieve remote code execution on SharePoint servers. CVE-2026-55040 bypasses authentication via JWT token validation weakness, granting site user or admin privileges. CVE-2026-63520 then enables RCE through Business Connectivity Services. Internet-exposed SharePoint instances face immediate risk. Historical context: 15 SharePoint vulnerabilities exploited since November 2021, eight used in ransomware campaigns. CVE-2026-45659 (separate flaw) confirmed in ransomware attacks as of August 26.

Urgency

🔴 Immediate

Recommended Actions

  • Apply Microsoft security updates for CVE-2026-55040 and CVE-2026-63520 immediately to all on-premises SharePoint Server instances
  • Audit and restrict Internet exposure of SharePoint servers; place behind VPN or zero-trust access controls where possible
  • Review SharePoint access logs for suspicious JWT token activity, admin enumeration attempts, and Business Data Catalog queries since August 11, 2026
  • Implement Microsoft's official SharePoint Server security-hardening guidance available in their security documentation
  • Monitor for indicators of compromise related to CVE-2026-55040 and CVE-2026-63520 using threat intelligence feeds from CISA, Defused, and Shadowserver